| 
							
							
								 Miroslav Stampar | 613242e298 | bug fix (dynamic markings were not restored in program rerun which potentially led to no data retrieved) | 2010-12-29 19:48:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8f32c740ff | code refactoring | 2010-12-29 19:39:32 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6700cabc36 | minor optimization | 2010-12-29 19:01:29 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 569e060aab | important improvement | 2010-12-26 13:20:52 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2d115e0350 | one more fix | 2010-12-24 18:44:13 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | edcf1a0872 | few bug fixes | 2010-12-24 18:40:48 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 96a06351a1 | minor fix (in testing phase raise404 should be set to False) | 2010-12-24 12:36:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2c23a59ba5 | fix for one of those more complex bugs (comparison was returning None while original page and/or page template were already had already DBMS error inside) | 2010-12-24 12:13:48 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | aab14fa2d3 | minor refactoring/cosmetics | 2010-12-24 11:06:57 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 23dc408901 | prioritization of tests based on DBMS error messages and some comments in common.py | 2010-12-24 10:55:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 017ea9e686 | update | 2010-12-23 14:06:22 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 73f33c1999 | bug fix of re-introduced bug (in multiple target mode sites with similar URI weren't skipped) | 2010-12-23 11:28:13 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8fc60215ed | lol. this was a pesky bug. heuristic wasn't working on one mssql test site and i couldn't find why. at end the problem was that when the HTTP code was raised (like 500) no parseResponse was called. | 2010-12-22 19:12:46 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 5228f336da | Minor fix for ctrl+c during detection phase | 2010-12-22 13:15:44 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 08c88495d0 | removed that ugly hack | 2010-12-22 13:09:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d974a966b8 | minor fix for end phase (Ctrl+C) | 2010-12-21 23:55:55 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0e68248f60 | minor update of heuristic check | 2010-12-21 12:56:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 16f1f4e13e | when doing dynamic checks there are cases when 404 can be raised (perfectly normal) | 2010-12-21 11:04:49 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | ad6b528b33 | Bit more verbose comment | 2010-12-21 10:47:39 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 416755c0b7 | minor adjustments | 2010-12-21 00:25:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e10670d9ac | added end detection phase choice into Ctrl+C list | 2010-12-20 23:34:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b34fe5c334 | no more need for such a huge timeout because any timeout exceptions will now be considered as a successful time-based attack (previously we wanted to get back to the program, hence there was such a huge timeout) | 2010-12-20 22:49:48 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | eaf8929085 | more minor updates | 2010-12-20 10:48:53 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | fd00ff7a82 | minor bug fix | 2010-12-20 10:37:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e9f1ecb9e7 | minor update | 2010-12-20 10:32:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 10a7a2dfb2 | kids, don't use this at home | 2010-12-20 10:13:14 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 4cb83654dc | minor update | 2010-12-18 16:28:21 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 05c6d661e8 | cosmetics | 2010-12-18 10:49:49 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 03220d34ba | added Ctrl+C check in detection phase | 2010-12-18 10:42:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | fe67d3827c | code refactoring and some fixes | 2010-12-18 09:51:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 323af45ce4 | added one more time request payload to confirm test results | 2010-12-17 07:53:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e3fa3b0e8e | fix for a minor bug reported by nightman (AttributeError: 'NoneType' object has no attribute 'getFingerprint') | 2010-12-17 07:48:32 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f8a01ddaf8 | minor update | 2010-12-15 11:21:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 63f5c35c23 | bug fix | 2010-12-15 10:02:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d5fb921154 | removed debug print | 2010-12-09 20:08:59 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0eb2c408a9 | code refactoring | 2010-12-09 16:49:02 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | df5f6bc1b7 | Little precaution | 2010-12-09 14:06:43 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 5fb04515d3 | Added hidden (for the moment) switch --technique | 2010-12-09 13:47:17 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 0c01be0eeb | Ugly work-around to avoid unescaping WAITFOR DELAY time between single quotes (unescaped CHAR(..) value does not work). | 2010-12-09 00:34:02 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 9c61adb21d | Cosmetics | 2010-12-09 00:26:06 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 10ef2b5de8 | Minor bug fix | 2010-12-08 23:09:42 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 81c16926c1 | code refactoring some more | 2010-12-08 14:46:07 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ed09c53ee4 | minor minor update | 2010-12-08 14:27:37 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1ae2fa7f1a | update regarding time based payloads | 2010-12-08 11:26:54 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a4a63f5b1e | minor update | 2010-12-07 23:49:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 293ce18fed | two major bug fixes regarding time calculation (previously comparison was also a part of "delta", which screwed results in cases with large pages; other was a standard distribution based one) | 2010-12-07 23:32:33 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 575e50673b | minor update | 2010-12-07 19:27:01 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 398b82644a | little explanation | 2010-12-07 19:25:26 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | dc651d59ec | little mathematics here and there (used "Rules for normally distributed data") | 2010-12-07 19:19:12 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | ee72838231 | Removed debug print | 2010-12-07 17:19:29 +00:00 |  |