Miroslav Stampar
|
c3065f6ecc
|
minor fix
|
2010-12-29 20:38:56 +00:00 |
|
Miroslav Stampar
|
96c3ffd3d7
|
changing risk level to 0 - lots of MySQL databases around have information_schema unreadable, thus disabling first AND based error payload
|
2010-12-27 19:02:13 +00:00 |
|
Miroslav Stampar
|
2c8115eed9
|
further improvement for ms access table dumping
|
2010-12-26 01:04:30 +00:00 |
|
Miroslav Stampar
|
fb099615e2
|
minor update
|
2010-12-25 11:16:35 +00:00 |
|
Miroslav Stampar
|
272476773f
|
getPageTextWordsSet on tableExists is pretty powerful stuff
|
2010-12-25 09:37:33 +00:00 |
|
Miroslav Stampar
|
706d8e0b88
|
development update (basic ms access dumping implemented)
|
2010-12-24 19:53:11 +00:00 |
|
Miroslav Stampar
|
edcf1a0872
|
few bug fixes
|
2010-12-24 18:40:48 +00:00 |
|
Miroslav Stampar
|
3043ed095a
|
bug fix (those two regexes where too generic making false MS ACCESS positives here and there)
|
2010-12-24 00:11:10 +00:00 |
|
Miroslav Stampar
|
5a0aef0f33
|
fix for a case: Microsoft OLE DB Provider for ODBC Drivers error '80040e14' [MySQL][ODBC 3.51 Driver][mysqld-5.1.31-community] - it was wrongly error message recognized as MS SQL Server
|
2010-12-23 09:53:13 +00:00 |
|
Miroslav Stampar
|
8fc60215ed
|
lol. this was a pesky bug. heuristic wasn't working on one mssql test site and i couldn't find why. at end the problem was that when the HTTP code was raised (like 500) no parseResponse was called.
|
2010-12-22 19:12:46 +00:00 |
|
Bernardo Damele
|
c9ab8ae60e
|
Bug fix to properly identify if current user is DBA (--is-dba) on MySQL
|
2010-12-22 14:06:01 +00:00 |
|
Bernardo Damele
|
e791f8f2b7
|
Minor fix
|
2010-12-20 10:33:24 +00:00 |
|
Miroslav Stampar
|
bfdc4fa000
|
new error vector for MS SQL (from David Guimaraes' mail)
|
2010-12-17 19:00:20 +00:00 |
|
Miroslav Stampar
|
3ee44584d4
|
i've found a way! thank you hesus! fyea (ASC(MID) was just crashing when MID returned 'empty string')
|
2010-12-14 12:57:59 +00:00 |
|
Bernardo Damele
|
207f63cebc
|
Prepare for UNION query tests at detection phase
|
2010-12-13 21:31:34 +00:00 |
|
Miroslav Stampar
|
33639578ee
|
minor update for MS Access
|
2010-12-12 15:25:19 +00:00 |
|
Miroslav Stampar
|
b1babeefe5
|
update regarding dumping of tables with blind on Sqlite
|
2010-12-11 22:00:16 +00:00 |
|
Miroslav Stampar
|
acc7d6d40c
|
fix
|
2010-12-11 11:03:32 +00:00 |
|
Miroslav Stampar
|
ac9080c07b
|
update
|
2010-12-11 08:24:29 +00:00 |
|
Miroslav Stampar
|
fe2039f5ba
|
coollyy little commits
|
2010-12-10 11:32:46 +00:00 |
|
Miroslav Stampar
|
7e2984b4b6
|
added stacked query support for Oracle
|
2010-12-09 15:24:48 +00:00 |
|
Bernardo Damele
|
4bb40c0a06
|
Higher the level for Oracle stacked tests just in case the SQL inj is within a PL/SQL function ('cause of no support for stacked queries by design on Oracle)
|
2010-12-09 15:14:18 +00:00 |
|
Miroslav Stampar
|
d8edc5b244
|
adding stacked-query vector for Firebird
|
2010-12-09 15:11:21 +00:00 |
|
Bernardo Damele
|
13b522efc2
|
Added error-based support for MySQL < 5.0 - closes #14
|
2010-12-09 15:09:03 +00:00 |
|
Miroslav Stampar
|
5aafd19957
|
added vector for SQLite's stacked query payload
|
2010-12-09 15:06:40 +00:00 |
|
Miroslav Stampar
|
71761ba9a5
|
another fix for another beautiful heavy query payload which took a few 100 megs and 5 mins to run
|
2010-12-09 10:35:18 +00:00 |
|
Miroslav Stampar
|
094baadc5b
|
bug fix (in SELECT based heavy queries COUNT(*) should be used; otherwise multiple row error happens without proper delay)
|
2010-12-09 10:17:04 +00:00 |
|
Bernardo Damele
|
3b293c4ea7
|
Added possible stacked queries time-based blind vector for MSSQL
|
2010-12-08 23:55:42 +00:00 |
|
Bernardo Damele
|
f5ce739bdf
|
Added support for time-based blind SQL injection via stacked queries too. Need to add vectors for some DBMS yet.
|
2010-12-08 23:52:31 +00:00 |
|
Miroslav Stampar
|
69c4f94980
|
update
|
2010-12-08 15:40:01 +00:00 |
|
Miroslav Stampar
|
ad00fe13c1
|
another fix for MySQL time based payloads
|
2010-12-08 12:00:27 +00:00 |
|
Miroslav Stampar
|
8227e6d3cf
|
bug fix for BENCHMARK time-based vectors
|
2010-12-08 11:49:55 +00:00 |
|
Bernardo Damele
|
8ff7c9a5a1
|
Works on Oracle's GROUP BY too
|
2010-12-07 17:17:01 +00:00 |
|
Miroslav Stampar
|
4f01d4c109
|
number crunching based time payloads are now affected by conf.timeSec
|
2010-12-07 13:24:18 +00:00 |
|
Miroslav Stampar
|
d0936bc8ed
|
adding vectors for SQLite time-based payloads
|
2010-12-07 13:14:56 +00:00 |
|
Bernardo Damele
|
54b8cb76a1
|
Messed up with my last merge, all fixed now
|
2010-12-07 12:59:53 +00:00 |
|
Miroslav Stampar
|
b38a634d95
|
bug fix
|
2010-12-07 12:55:31 +00:00 |
|
Bernardo Damele
|
7c32db6e9d
|
Forgot when merged with my last commit
|
2010-12-07 12:52:09 +00:00 |
|
Bernardo Damele
|
acac0d346f
|
Minor bug fixes and adjustments
|
2010-12-07 12:45:45 +00:00 |
|
Miroslav Stampar
|
2b2b7dc3a6
|
added vectors for time-based Firebird payloads
|
2010-12-07 12:20:48 +00:00 |
|
Miroslav Stampar
|
36a7fca8d5
|
added time-based payload vector for MSSQL
|
2010-12-07 12:06:25 +00:00 |
|
Miroslav Stampar
|
485981c619
|
added vectors for PostgresSQL time-based payloads
|
2010-12-07 11:57:33 +00:00 |
|
Miroslav Stampar
|
f9085e01e7
|
added vectors for Oracle time-based payloads
|
2010-12-07 11:47:29 +00:00 |
|
Miroslav Stampar
|
3d87489de5
|
minor update
|
2010-12-07 08:05:03 +00:00 |
|
Miroslav Stampar
|
90b776c1a2
|
update
|
2010-12-07 00:58:54 +00:00 |
|
Miroslav Stampar
|
0da1ebde7d
|
introducing PostgreSQL time based blind
|
2010-12-07 00:51:14 +00:00 |
|
Miroslav Stampar
|
1ba98dc9ec
|
found a fix for a OR time-based MySQL payload :)
|
2010-12-07 00:31:46 +00:00 |
|
Miroslav Stampar
|
61f82fd274
|
introducing [DELAYED] for heavy query time based payloads when response time is non-deterministic
|
2010-12-07 00:27:26 +00:00 |
|
Bernardo Damele
|
32f1909131
|
Some more "advanced" boundaries
|
2010-12-06 23:15:41 +00:00 |
|
Miroslav Stampar
|
84a038d0a3
|
added one more subtag
|
2010-12-06 23:10:38 +00:00 |
|