| 
							
							
								 Miroslav Stampar | f46baac70b | bug fix (when comment is None this was errornous) | 2011-08-17 10:58:29 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 702ed73a65 | Added --code switch to match in boolean-based tests against the HTTP response code | 2011-08-12 16:48:11 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | fff4c34e33 | Search for --string and --regexp matches also in HTTP response headers | 2011-08-12 15:33:37 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2ad267132a | minor update for empty normal responses (like AJAX requests) | 2011-08-05 10:55:21 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f7562da754 | from now on proper union column count should be displayed in injection info output | 2011-08-03 10:34:50 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 07afcd5440 | fix for a bug reported by Ahmed Shawky (when user uses --suffix intermixing test default comments with the provided suffix is a big no no) | 2011-08-02 18:20:21 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 07c3d4fb18 | minor adjustment | 2011-08-02 17:35:43 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 6cbb927012 | Partial fix for -o not resumed at following runs if missing from command line | 2011-07-25 11:05:49 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0d6afca7db | adding new switch '--smart' by request | 2011-07-10 15:16:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c517e97a44 | few fixes and minor cosmetics | 2011-07-08 06:02:31 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | aedcf8c8d7 | Changed homepage address | 2011-07-07 20:10:03 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 0d28c1e9e7 | cosmetics | 2011-07-06 20:41:13 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 93b296e02c | few bug fixes (NTLM credential parsing was wrong), some switch reordering (few Misc to General), implemented --check-waf switch (irony is that this will also be called highly experimental/unstable while other things will be called "major/turbo/super bug fix/implementation") | 2011-07-06 05:44:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b8ffcf9495 | few fixes here and there and multi-core processing for dictionary based hash attack | 2011-07-04 19:58:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8a8b94883b | minor update (that default quit in --batch was bothering me - my original idea and it was bad :) | 2011-06-27 14:14:49 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 36c96ef796 | Added DB2 support - patch provided by Sebastian Bittig | 2011-06-25 09:44:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c4cb367e65 | looks nicer (though --tor is implicitly converted into --proxy) | 2011-06-24 19:00:53 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2de88bd90b | minor update | 2011-06-24 17:19:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | eaa2a4202f | changing to: --crawl=CRAWLDEPTH | 2011-06-24 05:40:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 29314f425e | minor fix | 2011-06-20 13:42:31 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 07e2c72943 | adding Beautifulsoup (BSD) into extras; adding --crawl to options | 2011-06-20 11:32:30 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | f8c32cf6b9 | Moved folder | 2011-06-18 12:34:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a0129dcbcb | this is confusing for normal users (i've just get a mail where dude thinks that he needs to use tamper script because of this :) | 2011-06-17 16:52:39 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6b1d5a0ab8 | minor fix | 2011-06-16 14:11:30 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 25b923bbc3 | minor fixes and minor updates | 2011-06-16 12:12:30 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 4d51fa8155 | minor update planned for a long time (in case of heuristic test was positive warn the user properly at the end if program fails) | 2011-06-15 17:37:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9331abb96f | minor update | 2011-06-11 08:33:36 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 71093b1cad | adding one more user friendly message | 2011-06-09 09:58:42 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | d217cf71b2 | Minor bug fix | 2011-06-08 23:32:44 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 70cac24909 | Cosmetics | 2011-06-08 15:31:27 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d8155dfae9 | change by request | 2011-06-08 14:44:11 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 0d3e8a76d8 | Cosmetics and a missing param | 2011-06-08 14:40:42 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 4a9640160e | more concise | 2011-06-08 14:35:23 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | cce3208b35 | Cleanup | 2011-06-08 14:15:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1c633b7351 | i am tired of pressing hundred times Ctrl+C in testing phase if --batch is specified | 2011-06-07 22:14:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 97d8c60c3f | better language | 2011-06-03 15:58:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0a620bf322 | more info to the user | 2011-06-03 15:43:50 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8aa5625cd0 | proper fix related to the last commit | 2011-06-01 23:00:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | fd57aae779 | bug fix (until this moment we had UNION unfunctional for MSSQL) | 2011-06-01 22:47:54 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b7088440c2 | better sentence | 2011-05-30 22:47:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a8b58afdb2 | minor update | 2011-05-27 08:21:02 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 48f52d7697 | minor beautification | 2011-05-27 08:16:14 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 45caadbd4a | important update - finally found what was causing headache for UNION payloads in noticeable number of cases | 2011-05-26 21:54:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 97bd5355dd | minor update | 2011-05-26 21:18:55 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5d56e89cf5 | minor update | 2011-05-26 21:08:46 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 06108b6da6 | minor update related to the last commit | 2011-05-26 20:58:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 4f46a5ab63 | minor usability enhancement regarding warning for --text-only switch | 2011-05-26 20:48:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a1fd2898a0 | added friendly tip message for url encoding GET and POST payloads | 2011-05-25 11:10:52 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | bec2c04671 | helping dummy users | 2011-05-24 17:15:25 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | faa74cd2bc | introducing results file for multiple target mode | 2011-05-15 22:21:38 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f11d5c91e3 | minor update so that only one DNS request per scan is being done (before this commit there were two) | 2011-05-12 14:32:39 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 120b0d756e | unfix | 2011-05-10 21:33:06 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | deae534ee7 | minor refactoring | 2011-05-10 20:44:36 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 3a8309c4b0 | Major bug fix to detect UNION query technique and various improvements to parsing and using of --union-char and --union-cols switches | 2011-05-10 15:34:54 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 9955483052 | Major improvement for --dump. Minor improvement for --dump-all.
Minor bug fix for infinite loop | 2011-05-08 02:08:18 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 8179fd63c0 | Minor fix | 2011-05-07 23:48:03 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 1151af52bb | More fix for save/resume of --technique | 2011-05-07 21:08:14 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | aae140080e | SVN roll back, DB2 patch will be recommitted after testing: $ svn merge https://svn.sqlmap.org/sqlmap/trunk/sqlmap@HEAD https://svn.sqlmap.org/sqlmap/trunk/sqlmap@3847 . | 2011-05-06 10:27:43 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6e392b6054 | applying contributed patch for DB2 | 2011-05-06 09:30:39 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 2d8408c885 | More fix for --technique resume | 2011-05-05 16:38:46 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 6cff3e97f4 | cosmetics | 2011-05-02 21:48:08 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 06498796b9 | minor cosmetics | 2011-05-02 20:51:53 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 955dbc85e7 | Minor variable rename | 2011-04-30 15:29:59 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | f56d135438 | Minor code restyling | 2011-04-30 13:20:05 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | a5968fff3e | Added --count switch to count the number of entries for a specific table (when -T is provided), all database's tables (when only -D is provided) or all databases' tables when neither -D nor -T are provided | 2011-04-30 00:22:22 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | a23ca952e4 | Actually brute-force switches make more sense just after their "normal" version. Also, getSchema() method is preferably to be called before getColumns(), see next commit for reason | 2011-04-29 21:09:07 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | edac0b2558 | Added switch --schema to enumerate DBMS schema and now --columns does not require a mandatory table (-T) anymore, instead it will act as an alias for --schema | 2011-04-28 23:59:00 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 441c288dd9 | cosmeticados | 2011-04-25 00:36:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7b3b9e6a87 | it seems that this was indeed not meant to be here | 2011-04-22 15:07:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 304500a2e8 | implemented checkFalsePositives method (simple Turing like tests) | 2011-04-22 12:24:16 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | eabb5a2ba7 | More adjustments to the error message when no sql injections are detected | 2011-04-21 22:04:20 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 6d07dddf60 | updated doc and minor layout adjustments | 2011-04-21 21:53:35 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 770b1523ff | More verbose output when no SQL injections are detected | 2011-04-21 21:31:16 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | edc2d75702 | Cosmetics and major bug fix | 2011-04-21 21:15:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | df0331fe9b | some more refactoring | 2011-04-19 23:04:10 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9b0db33cc5 | initial page request can result in unwanted lag (e.g. slow DNS response,...), hence it's response time shouldn't be a part of response time statistical model | 2011-04-19 08:55:38 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0387654166 | update of copyright string (until year) | 2011-04-15 12:33:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 21114d1748 | added IGNORE_PARAMETERS to skip testing of state/session web server parameters | 2011-04-13 19:01:02 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2db2e9b6a2 | now GET forms are also prone to "do you want to fill with random values" | 2011-04-11 11:38:41 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 5b21352656 | cosmeticados ;) | 2011-04-08 10:39:07 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | c6b9d89d31 | Accept [RANDNUM] as <char> in payloads.xml and handle it accordingly | 2011-04-07 11:10:35 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 05d12790f1 | closes #219 - unhidden switch --technique and adapted code accordingly (renamed conf.technique to conf.tech to fit properly in the -h help message) | 2011-04-06 14:41:44 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | bbd4c128b0 | minor update related to the last commit | 2011-04-01 22:19:42 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0916117447 | improvement of error-based testing (no more sqlmap aborting on error-based payloads which happens very often on MySQL servers); also, minor improvement on brute forcing of column names | 2011-03-30 18:32:10 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | dd01d66f13 | proper update regarding last commit | 2011-03-29 22:10:08 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 4d78eac938 | revert of that thingy as requested by Bernardo | 2011-03-29 10:06:35 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e8debbe724 | minor cosmetics and one minor fix (|= is a nono with None) | 2011-03-29 06:38:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 86f93713d3 | fix for a bug reported by m4l1c3 (object of type 'NoneType' has no len()) and minor update | 2011-03-29 06:25:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | bf0e3c4662 | improvement for --forms with empty fields | 2011-03-28 22:48:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1e22ff45de | minor update regarding testing of GET parameters if --data and/or --forms is used | 2011-03-28 16:14:08 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | bd75fd26e9 | implementing a --page-rank switch as requested by l0rda@l0rda.biz | 2011-03-23 11:57:57 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b5c9ccb755 | Oracle XML based error payload has problems with char $ as with space | 2011-03-21 13:13:12 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 970cde5a8a | minor update regarding last commit | 2011-03-17 09:23:46 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e64f225e65 | minor refactoring | 2011-03-11 20:16:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8edc3b3302 | further update regarding last commit | 2011-03-03 10:39:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 90582ed7dc | minor change | 2011-02-21 11:35:21 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6cdf08b81c | minor fix | 2011-02-17 21:51:40 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 22cd49a217 | --technique can now be something like 123 which includes both techniques 1, 2 and 3 | 2011-02-17 21:39:16 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7ebc1ab90a | minor cosmetics | 2011-02-17 08:59:14 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 50d25c3b4d | update regarding explicit testing of ua and referer when using -p | 2011-02-13 21:58:48 +00:00 |  |