| 
							
							
								 Bernardo Damele | ba3a8a69d4 | More statements to exclude from unescap'ing | 2011-02-07 00:33:54 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 3719f085ae | Added back-end dbms' OS based methods to Backend object - will be used for refactoring | 2011-02-07 00:21:17 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 2e00656235 | Minor fix | 2011-02-07 00:20:23 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | bf5ca4bd9a | No point in unescaping the expression also in suffixQuery() also 'cause it will exit sqlmap if the parameter value is a string hence injection payload starts with single quote (') | 2011-02-06 23:30:43 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 061f56daf9 | More adjustments related to unescape() and cleanupPayload(). Minor code cleanup related to error-based payload. | 2011-02-06 23:27:56 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 6a71629575 | Converted from DOS format (\n\r to \n only) | 2011-02-06 23:25:55 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 0800d9e49b | Major bug fix for semi-centralize unescape() and cleanupPayload() into prefixQuery() and suffixQuery() | 2011-02-06 22:58:12 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 9eac2339ca |  | 2011-02-06 22:55:26 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | f3d6be7868 | Code cleanup | 2011-02-06 22:32:44 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 078a2207cc | few reverts | 2011-02-06 22:10:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b9b2fe0e7c | little cleanup | 2011-02-06 21:52:39 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c4c2cf1d58 | can't stay as it is right now. temporary disabling. | 2011-02-06 21:17:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d2b96a66a2 | one more update regarding last few "unescape" related commits | 2011-02-06 20:23:23 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 6191a7f26f | Major fix for a silent bug | 2011-02-06 15:53:43 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | c44978862e | Minor reordering of what gets saved into the injection object | 2011-02-06 15:20:44 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 412a97b7fe | fix for a bug reported by ahmed@isecur1ty.org (TypeError: unsupported operand type(s) for -: 'float' and 'NoneType') | 2011-02-05 14:17:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 4df8a03c04 | using OrderedDict to store parameters in order of appearance | 2011-02-04 18:07:21 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | acb986ae80 | minor refactoring | 2011-02-04 17:40:55 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | fec88f6a6d | Minor fix | 2011-02-04 15:57:53 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 09e88cfb19 | fix for a bug reported by zack.payton@executiveinstruments.com (object of type 'NoneType' has no len()) | 2011-02-04 14:05:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f83f1a1e06 | minor just in case update | 2011-02-04 13:08:54 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c69b76776e | minor refactoring | 2011-02-04 13:04:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | accf4e6ce0 | one important fix (URI injection parameter '*' now can go anywhere) | 2011-02-04 12:43:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c19d481bb1 | little clean up | 2011-02-04 12:25:14 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c229efba05 | revert | 2011-02-04 11:33:21 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d211def899 | minor adjustment (accepting strange new looking uri formats) | 2011-02-04 10:55:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1af418d444 | huge bug fix | 2011-02-04 10:18:26 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e4933f0c92 | refactoring | 2011-02-03 23:25:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9a1a28c804 | adding comments to filtering function | 2011-02-03 23:09:08 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1aecbe6b08 | minor refactoring (now at the most basic level at least junky <script> and <style> tags are removed for the sake of better blind based detection) | 2011-02-03 22:59:26 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e5f54644f0 | minor "statistical" update | 2011-02-03 16:59:49 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3bd6e538f8 | more appropriate | 2011-02-03 16:48:27 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3a13fd87fd | new UNION column detection is going into wild | 2011-02-03 16:16:38 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b56a77e573 | removing obsolete switches (--threshold, --excl-reg, --excl-str) | 2011-02-03 15:55:19 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 253a8d0679 | Minor bug fix | 2011-02-03 15:24:36 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0edb4ee314 | minor fix | 2011-02-03 13:28:10 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1b9850b73a | revert of last commit (conf dictionary has a method "update" which caused if conf.update to True always :) ) | 2011-02-03 12:21:29 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5edba2ffbc | minor change (conf.updateAll to conf.update) | 2011-02-03 11:13:39 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 402c1b622e | removing urlencode from UA | 2011-02-02 15:18:06 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5f49e20cc8 | adding --random-agent and removing -a | 2011-02-02 14:51:12 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2dae57a56d | cosmetics | 2011-02-02 14:35:21 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6c87bd1c63 | added maskSensitiveData function | 2011-02-02 14:25:16 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 5f0114a2a8 | Minor bug fix | 2011-02-02 14:06:40 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8134c2154a | adding WHERE enum for payloads | 2011-02-02 13:34:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d6c9515f78 | minor update | 2011-02-02 13:03:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 847b648e4a | minor update | 2011-02-02 12:42:55 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e73a147fb5 | minor update | 2011-02-02 11:49:59 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e33428b833 | adding __findUnionCharCount function | 2011-02-02 11:22:35 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 99aa38b58f | minor refactoring | 2011-02-02 10:10:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 23c95107ed | we must do this because people tend to use ignorantly huge number threads resulting in lots of CRITICAL (timeout) connection messages (also, avoiding DoS) | 2011-02-02 09:24:37 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | af99105c27 | lol. sybase and maxdb were just ignored while fingerprinted because they weren't in dbmsDict screwing half of dbms related functions (most notably aliasToDbmsEnum) | 2011-02-01 22:45:38 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | a37f5e05b9 | Refactoring | 2011-02-01 22:27:36 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 9b342a4c95 | Bug fixes and proper packing/unpacking of custom statements and predefined queries for both error-based and UNION query techniques. Now it deals in UNION query also with --start and --stop and resume has been enhanced for both techniques too. | 2011-02-01 22:07:42 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 2619e4895f | Properly handle --technique at save/resume phase | 2011-02-01 22:05:48 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 3d966bd569 | You never know.. | 2011-02-01 22:05:12 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | d875d848ce | Better sort | 2011-02-01 22:04:48 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 705d45f4db | minor cosmetics | 2011-02-01 11:10:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 196e2d35b2 | maybe we could ask user "are you willing to import local data content into error report" and use this function respectably | 2011-02-01 11:06:56 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 6761933f75 | Just.. cosmetics ;) | 2011-01-31 22:51:14 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 35b6d7278a | minor update | 2011-01-31 22:50:54 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 25c175a9a5 | minor bug fix | 2011-01-31 22:34:57 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | b04e1a0313 | More detailed message for unhandled exception | 2011-01-31 21:23:40 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 2fd9621499 | Minor adjustments Cosmetics | 2011-01-31 21:22:39 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | ec9ebb3479 | Set threads to 4 when optimization switch is provided, -o | 2011-01-31 21:21:13 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 8397c526d8 | Minor adjustment | 2011-01-31 21:20:23 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | e3a3ae11cc | Proper return from error-based technique enumeration | 2011-01-31 21:13:29 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | fa58a9c86b | update (now URIs like www.site.com/id82 are automatically treated as possible URI injectable) | 2011-01-31 20:36:01 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 777a19cfa9 | LOL. removing that debug 'True' | 2011-01-31 16:22:55 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a80fe28631 | one more thing ;) | 2011-01-31 16:21:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 933d701667 | cosmetics | 2011-01-31 16:14:44 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b1dc928e68 | implemented validation for time-based inference | 2011-01-31 16:07:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 25463bc67c | fix for a bug (--predict-output) noticed by Bernardo | 2011-01-31 15:00:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 60a2364f2b | now union technique parses headers too | 2011-01-31 12:41:39 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8ef47307db | added checking of header values for GREP (error); still UNION to do | 2011-01-31 12:21:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a6f2cd56ff | removed junky import | 2011-01-31 11:59:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | fb3513650d | adding ID properties | 2011-01-31 11:41:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f9eac97fe8 | refactoring of MSSQL XML banner parsing | 2011-01-31 11:38:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7175efcae1 | another minor cosmetic update | 2011-01-31 10:59:51 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 97328c3104 | minor fix | 2011-01-31 10:54:13 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5e768be509 | minor bug fix | 2011-01-31 09:34:54 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f7feebe0df | fix for a bug reported by malice.anon@gmail.com (TypeError: encode() takes no keyword arguments) | 2011-01-31 09:28:16 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 2a0b03e5c6 | Unused import | 2011-01-30 17:07:27 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | fc9c626f9e | minor refactoring (removed URL_ENCODE_PAYLOAD) | 2011-01-30 17:03:06 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 21e7223779 | perhaps this is better english | 2011-01-30 16:34:13 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 8278d821ac | Another layout adjustment | 2011-01-30 16:23:19 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 71d82e6f57 | Minor layout adjustment | 2011-01-30 16:19:58 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 02e5c4b1e6 | Minor bug fix for --sql-query/-shell with error-based technique | 2011-01-30 14:19:50 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | bc8f1142c9 | minor revert | 2011-01-30 11:41:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ddf23ba7cc | refactoring | 2011-01-30 11:36:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3060c369a5 | minor fix for previous commit | 2011-01-30 07:44:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1abf354630 | minor update | 2011-01-30 07:41:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d63339ca26 | minor bug fix | 2011-01-30 07:34:07 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e8883de2c6 | minor update regarding unicode decoding of supplied arguments | 2011-01-29 23:01:39 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 367d0639f0 | refactoring (class names should always be Capital cased) | 2011-01-28 16:36:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ddd296030d | added some more info to unhandled exception message(s) | 2011-01-28 16:15:45 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a184a4c772 | major of majors bug fix | 2011-01-28 14:31:25 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0f4fb156d3 | major bug fix | 2011-01-28 14:09:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b98cbeee04 | page for handling binary files | 2011-01-27 22:00:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8e74c571bc | centralization of urlencoding should be (only) in connect.py and we are from now on handling non-urlencoded data at other levels | 2011-01-27 19:44:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 49aeb41be8 | quick bug fix for FALSE positives with UNION based technique | 2011-01-27 18:49:44 +00:00 |  |