Miroslav Stampar
|
bc79eec702
|
removed queriesfile.py, implemented XMLObject approach (still shell.py and udf.py TODO)
|
2010-10-21 13:13:12 +00:00 |
|
Miroslav Stampar
|
be443c6947
|
refactoring regarding __START__,...
|
2010-10-21 09:51:07 +00:00 |
|
Miroslav Stampar
|
2668c95ef4
|
added default HTTP version used by httplib and urllib2
|
2010-10-21 09:10:07 +00:00 |
|
Bernardo Damele
|
7f1aa3b94f
|
Removed unused imports
|
2010-10-20 22:48:51 +00:00 |
|
Miroslav Stampar
|
934adb5e8d
|
code refactoring
|
2010-10-20 09:09:04 +00:00 |
|
Miroslav Stampar
|
b032fdbf74
|
added randInt to error injection vectors
|
2010-10-20 08:56:58 +00:00 |
|
Miroslav Stampar
|
dabbcf9e23
|
fix for that 'Subquery returns more than 1 row'
|
2010-10-20 08:50:05 +00:00 |
|
Miroslav Stampar
|
82f44989ce
|
update of error based injection and bug fix for --roles on MSSQL server
|
2010-10-20 06:40:33 +00:00 |
|
Miroslav Stampar
|
8776db872c
|
minor refactoring
|
2010-10-19 23:05:24 +00:00 |
|
Miroslav Stampar
|
1b376c99a6
|
removed temp dictionary and replaced with kb.misc
|
2010-10-19 23:00:19 +00:00 |
|
Miroslav Stampar
|
7927e97007
|
update
|
2010-10-19 18:34:57 +00:00 |
|
Miroslav Stampar
|
415524bd5a
|
remove --error, now it's only --error-test (it needs to return True to be able to use it)
|
2010-10-19 18:34:14 +00:00 |
|
Miroslav Stampar
|
4009ef385e
|
more update regarding error based injection support
|
2010-10-19 18:17:34 +00:00 |
|
Miroslav Stampar
|
b2e0b615f8
|
fix for that MySQL checking
|
2010-10-19 17:38:39 +00:00 |
|
Miroslav Stampar
|
34d7de1d46
|
cosmetics
|
2010-10-19 15:28:54 +00:00 |
|
Miroslav Stampar
|
d7622bb9cf
|
major fix for MySQL error based injections
|
2010-10-19 15:17:16 +00:00 |
|
Miroslav Stampar
|
80505de15b
|
now --users work on Oracle and Postgre (tested)
|
2010-10-19 14:56:57 +00:00 |
|
Miroslav Stampar
|
4bc541ec3c
|
error based update
|
2010-10-19 14:47:13 +00:00 |
|
Miroslav Stampar
|
d0ebe428da
|
i've left error flag
|
2010-10-19 14:12:34 +00:00 |
|
Miroslav Stampar
|
bf850af2d8
|
fix for Oracle error based query "space" problem
|
2010-10-19 14:10:09 +00:00 |
|
Miroslav Stampar
|
6a8b1046d4
|
first successfull run of error based sqlmap in history :). tested --banner, --current-user, --current-db on 4 major DBMSes. still hidden from users (turn on flag error in getValue() in inject.py)
|
2010-10-19 12:02:04 +00:00 |
|
Miroslav Stampar
|
8b8fff41fe
|
cosmetics (adding html parsed DBMS) regarding heuristic check
|
2010-10-18 12:11:16 +00:00 |
|
Bernardo Damele
|
36bc410333
|
Minor bug fix
|
2010-10-18 09:50:23 +00:00 |
|
Miroslav Stampar
|
149837ebf5
|
added the same for proxy authorization header
|
2010-10-18 09:02:56 +00:00 |
|
Miroslav Stampar
|
aaebb4336e
|
fix for Bug #202
|
2010-10-18 08:54:08 +00:00 |
|
Miroslav Stampar
|
dcb9c2103a
|
just in case update
|
2010-10-15 11:20:19 +00:00 |
|
Bernardo Damele
|
5f6d88a418
|
Minor comment
|
2010-10-15 11:17:17 +00:00 |
|
Bernardo Damele
|
c5e385f77a
|
More layout adjustments
|
2010-10-15 10:28:34 +00:00 |
|
Miroslav Stampar
|
207bef7f19
|
fix for that SQLite3 vs SQLite2 issue
|
2010-10-15 09:39:41 +00:00 |
|
Miroslav Stampar
|
4f7f20b94f
|
sorry, cosmetics
|
2010-10-14 23:18:29 +00:00 |
|
Bernardo Damele
|
1674142d82
|
Minor cosmetic fixes
|
2010-10-14 15:28:54 +00:00 |
|
Miroslav Stampar
|
8b48833136
|
large commit with copyright header modifications
|
2010-10-14 14:41:14 +00:00 |
|
Miroslav Stampar
|
162d01abed
|
commit of all sorts (bug fix for heuristics and URI injections, fine tunning of tampering modules with SQL keywords,...)
|
2010-10-14 11:06:28 +00:00 |
|
Miroslav Stampar
|
dc50543ea4
|
major bug fix for --keep-alive option in multithreading mode (that 'shitty' _headers = {} made a one shared object for all connection objects)
|
2010-10-13 23:01:23 +00:00 |
|
Miroslav Stampar
|
36ef8ca575
|
bug fix
|
2010-10-13 22:42:48 +00:00 |
|
Miroslav Stampar
|
02a14d4c45
|
added Referer (part of Feature #37)
|
2010-10-13 22:08:09 +00:00 |
|
Miroslav Stampar
|
34580f56fc
|
added --tamper option
|
2010-10-12 22:45:25 +00:00 |
|
Miroslav Stampar
|
d2ec132469
|
added --text-only switch
|
2010-10-12 19:41:29 +00:00 |
|
Miroslav Stampar
|
1369529103
|
minor cosmetic update
|
2010-10-11 13:52:32 +00:00 |
|
Miroslav Stampar
|
43892cddbb
|
some updates
|
2010-10-11 12:26:35 +00:00 |
|
Miroslav Stampar
|
8fcad29bbf
|
new feature --forms (still unfinished)
|
2010-10-10 18:56:43 +00:00 |
|
Miroslav Stampar
|
adf2231edb
|
minor update
|
2010-10-06 13:38:03 +00:00 |
|
Miroslav Stampar
|
cf17debf79
|
changed connection message priority to critical (when verbose=0 it's displayed too)
|
2010-09-27 13:34:52 +00:00 |
|
Miroslav Stampar
|
13bb3a6212
|
minor update
|
2010-09-23 14:07:23 +00:00 |
|
Miroslav Stampar
|
da8ae5578b
|
first commit regarding Feature #144
|
2010-09-22 11:56:35 +00:00 |
|
Miroslav Stampar
|
975b96ae28
|
minor refactoring
|
2010-09-16 09:47:33 +00:00 |
|
Miroslav Stampar
|
1741801ade
|
implementation of HEAD/Range methods
|
2010-09-16 09:32:09 +00:00 |
|
Miroslav Stampar
|
b745331974
|
added null connection check
|
2010-09-16 08:43:10 +00:00 |
|
Miroslav Stampar
|
ecd6b573f7
|
added method parameter to the queryPage function
|
2010-09-15 14:17:17 +00:00 |
|
Miroslav Stampar
|
34a8cd75e3
|
added support for setting HTTP method manualy
|
2010-09-15 12:45:41 +00:00 |
|