Miroslav Stampar
|
45bdefd29b
|
Update of copyright
|
2015-01-06 15:02:16 +01:00 |
|
Miroslav Stampar
|
c5b71cff10
|
Some filtering
|
2014-08-21 01:12:44 +02:00 |
|
Miroslav Stampar
|
c2f14e57e7
|
Patch for an Issue #740
|
2014-06-29 00:27:23 +02:00 |
|
Miroslav Stampar
|
0f581ccb6c
|
Minor fix
|
2014-05-13 15:36:28 +02:00 |
|
Bernardo Damele
|
9f838c3d5b
|
typo fix
|
2014-03-21 11:37:34 +00:00 |
|
Bernardo Damele
|
8091a88d3e
|
minor code cleanup and bug fix
|
2014-03-21 11:35:30 +00:00 |
|
Bernardo Damele
|
c211255773
|
replaced outfile with dumpfile so works even if the original statement outputs blob
|
2014-03-21 11:01:57 +00:00 |
|
Miroslav Stampar
|
d405fc1157
|
Minor update (for the consistency sake)
|
2014-02-16 22:04:12 +01:00 |
|
Miroslav Stampar
|
58eac364a2
|
Bug fix
|
2014-02-16 21:57:14 +01:00 |
|
Miroslav Stampar
|
dfa727cbc5
|
Fix for a same bug mentioned in last commit
|
2014-02-16 21:47:14 +01:00 |
|
Miroslav Stampar
|
43df4efd11
|
Bug fix (bad idea is to do os.path.join on web URLs - especially on Windows OS)
|
2014-02-16 21:44:57 +01:00 |
|
Bernardo Damele
|
be6767b3b0
|
minor fix for command execution via web shell
|
2014-02-10 09:59:57 +00:00 |
|
Miroslav Stampar
|
0e44132778
|
Removing unused imports
|
2014-02-01 21:49:12 +01:00 |
|
Bernardo Damele
|
1505f1dc74
|
removed useless sink
|
2014-01-13 23:55:32 +00:00 |
|
Bernardo Damele
|
124ebefc7f
|
code cleanup
|
2014-01-13 23:48:15 +00:00 |
|
Bernardo Damele
|
dfa9076a70
|
fixed and improved web shell upload in MySQL (it was actually broken since fc57b7565d )
|
2014-01-13 17:12:37 +00:00 |
|
Miroslav Stampar
|
e18796dbe1
|
Minor style update
|
2013-05-25 18:00:20 +02:00 |
|
Miroslav Stampar
|
8acf033715
|
Code refactoring
|
2013-03-19 19:24:14 +01:00 |
|
Bernardo Damele
|
614ff6029d
|
working on #396 - handle the case when we dont have a web backdoor/file stager for the language API, added a few more log messages to give further information about what is going on, minor bug fix to docRoot
|
2013-02-14 18:31:14 +00:00 |
|
Bernardo Damele
|
4b9d8ed673
|
reverted a previous commit as not all distributions create a link file /usr/bin/python2 to the Python interpreter
|
2013-02-14 11:32:17 +00:00 |
|
Bernardo Damele
|
a67ef4117f
|
make sure to use Python 2 interpreter when default system Python is version 3
|
2013-02-14 11:25:04 +00:00 |
|
Bernardo Damele
|
f4028bd7d2
|
minor adjustment
|
2013-01-23 02:10:38 +00:00 |
|
Bernardo Damele
|
adf97e630f
|
add possibility to provide a list of web server document root possible directories for web shell upload in --os-cmd and --os-shell for MySQL
|
2013-01-19 18:04:33 +00:00 |
|
Bernardo Damele
|
a43202f3c0
|
updated copyright
|
2013-01-18 14:07:51 +00:00 |
|
Miroslav Stampar
|
ca3d35a878
|
Some PEP8 related style cleaning
|
2013-01-10 13:18:44 +01:00 |
|
Bernardo Damele
|
65ed2304fd
|
comment update
|
2012-12-19 09:38:03 +00:00 |
|
Bernardo Damele
|
0037d52098
|
typo fix
|
2012-12-19 01:11:18 +00:00 |
|
Miroslav Stampar
|
df0f08bc6a
|
Cleaning some (web upload based) garbage
|
2012-12-13 13:19:47 +01:00 |
|
Miroslav Stampar
|
974407396e
|
Doing some more style updating (capitalization of exception classes; using _ is enough for private members - __ is used in Python specific methods)
|
2012-12-06 14:14:19 +01:00 |
|
Miroslav Stampar
|
7c7aff12c6
|
Update for an Issue #225
|
2012-10-30 01:26:19 +01:00 |
|
Miroslav Stampar
|
726de868e2
|
Fix for an Issue #225
|
2012-10-30 00:37:43 +01:00 |
|
Miroslav Stampar
|
5358d85d37
|
Important refactoring for web-based functionality
|
2012-10-29 15:09:05 +01:00 |
|
Miroslav Stampar
|
d6e16e8641
|
Minor update
|
2012-10-29 11:08:02 +01:00 |
|
Miroslav Stampar
|
359e734954
|
Minor refactoring
|
2012-10-29 10:48:49 +01:00 |
|
Bernardo Damele
|
0a4b6431a8
|
minor bug fix - issue #112
|
2012-07-21 16:51:01 +01:00 |
|
Bernardo Damele
|
dba0a96c2e
|
fall-back to UNION technique if web file stager was not uploaded with LIMIT
|
2012-07-20 17:11:22 +01:00 |
|
Bernardo Damele
|
cbe8f41746
|
minor code refactoring preparing for #96
|
2012-07-20 16:20:17 +01:00 |
|
Miroslav Stampar
|
6677da63cd
|
Fix for an Issue #88
|
2012-07-13 14:25:39 +02:00 |
|
Miroslav Stampar
|
c5ecc8b8db
|
Closing work on Issue #83
|
2012-07-13 11:23:21 +02:00 |
|
Miroslav Stampar
|
48f68bd076
|
First commit for Issue #83
|
2012-07-13 10:35:22 +02:00 |
|
Bernardo Damele
|
162da75a04
|
modified homepage address
|
2012-07-12 18:38:03 +01:00 |
|
Bernardo Damele
|
0702dd70b5
|
verify also that the web backdoor has been successfully uploaded
|
2012-07-11 14:08:51 +01:00 |
|
Miroslav Stampar
|
e948e4d45b
|
Some more refactoring
|
2012-07-06 17:18:22 +02:00 |
|
jekil
|
c39e5a85ba
|
Removed $id$ tags
|
2012-06-27 20:56:43 +02:00 |
|
Miroslav Stampar
|
61ad3b999a
|
fix for a crash with partial union and --hex
|
2012-03-14 10:31:24 +00:00 |
|
Miroslav Stampar
|
b3bd4144f5
|
removing of unused imports together with some general code refactoring
|
2012-02-22 10:40:11 +00:00 |
|
Miroslav Stampar
|
95f89ab63a
|
updating copyright date
|
2012-01-11 14:59:46 +00:00 |
|
Miroslav Stampar
|
ba5eff1de6
|
minor bug fix
|
2011-09-23 18:29:45 +00:00 |
|
Bernardo Damele
|
702ed73a65
|
Added --code switch to match in boolean-based tests against the HTTP response code
|
2011-08-12 16:48:11 +00:00 |
|
Bernardo Damele
|
aedcf8c8d7
|
Changed homepage address
|
2011-07-07 20:10:03 +00:00 |
|
Miroslav Stampar
|
9e453e8709
|
fix for a bug reported by nightman@email.de
|
2011-06-29 17:49:59 +00:00 |
|
Bernardo Damele
|
cd6ceb733e
|
Adjustment and refactoring for takeover via web backdoor
|
2011-06-08 14:16:53 +00:00 |
|
Miroslav Stampar
|
868fbe370b
|
minor beautification
|
2011-05-23 10:39:58 +00:00 |
|
Bernardo Damele
|
f56d135438
|
Minor code restyling
|
2011-04-30 13:20:05 +00:00 |
|
Bernardo Damele
|
d0dff82ce0
|
Minor code refactoring relating set/get back-end DBMS operating system and minor bug fix to properly enforce OS value with --os switch
|
2011-04-23 16:25:09 +00:00 |
|
Miroslav Stampar
|
0387654166
|
update of copyright string (until year)
|
2011-04-15 12:33:18 +00:00 |
|
Miroslav Stampar
|
8134c2154a
|
adding WHERE enum for payloads
|
2011-02-02 13:34:09 +00:00 |
|
Miroslav Stampar
|
430fd5cd63
|
minor fixes
|
2011-01-25 16:05:06 +00:00 |
|
Miroslav Stampar
|
818c9787b2
|
minor update
|
2011-01-23 21:20:16 +00:00 |
|
Miroslav Stampar
|
b18397fbc7
|
major revisit of --os-shell methods
|
2011-01-23 20:47:06 +00:00 |
|
Bernardo Damele
|
cffa17f5a6
|
Major bug fix - before it raised a traceback, now works.
|
2011-01-18 23:02:47 +00:00 |
|
Miroslav Stampar
|
1fa8f0cba7
|
code reviewing part 2
|
2011-01-15 12:53:40 +00:00 |
|
Miroslav Stampar
|
de54219571
|
code refactoring
|
2010-12-15 12:50:56 +00:00 |
|
Bernardo Damele
|
698f30e65e
|
Cosmetics
|
2010-12-13 21:34:35 +00:00 |
|
Bernardo Damele
|
da3fd17fc3
|
Adjustment to make it work also in OR based injection
|
2010-12-05 12:24:23 +00:00 |
|
Miroslav Stampar
|
6712f4da55
|
some refactoring and one less request for aspx maintanance during --os-shell
|
2010-11-24 14:20:43 +00:00 |
|
Miroslav Stampar
|
9579a97039
|
now ASPX works too for --os-shell
|
2010-11-24 11:38:27 +00:00 |
|
Bernardo Damele
|
17486e472a
|
Proper english (--postfix is now --suffix) and --string/--regexp does not necessarily need to match into the original response body, it might well be in the injected True condition only!
|
2010-11-17 22:00:09 +00:00 |
|
Miroslav Stampar
|
17f0609263
|
minor bug fix
|
2010-11-17 13:29:57 +00:00 |
|
Miroslav Stampar
|
2802923dbe
|
some improvements regarding --os-shell web server application choice
|
2010-11-17 11:45:52 +00:00 |
|
Miroslav Stampar
|
bec152609a
|
minor cosmetics and bug fix for Windows machines ('\\' is interpreted as \ and inside the script it can screw things up as it's a marker for a special character - thus '\\\\' is interpreted as \\ which represents special character \)
|
2010-11-17 09:33:05 +00:00 |
|
Miroslav Stampar
|
e7a66371f8
|
update regarding os shell-ing regarding JSP and ASPX
|
2010-11-16 13:46:46 +00:00 |
|
Miroslav Stampar
|
6adee3792a
|
removed all trailing spaces from blank lines
|
2010-11-03 10:08:27 +00:00 |
|
Bernardo Damele
|
bdb9c37a7e
|
Cosmetics
|
2010-10-25 15:17:59 +00:00 |
|
Bernardo Damele
|
f95098693f
|
Removed unused functions
|
2010-10-20 21:16:28 +00:00 |
|
Bernardo Damele
|
683184cc8f
|
Minor refactoring
|
2010-10-17 21:06:52 +00:00 |
|
Bernardo Damele
|
f54c134d22
|
Minor adjustment
|
2010-10-16 22:43:05 +00:00 |
|
Miroslav Stampar
|
4f7f20b94f
|
sorry, cosmetics
|
2010-10-14 23:18:29 +00:00 |
|
Miroslav Stampar
|
8b48833136
|
large commit with copyright header modifications
|
2010-10-14 14:41:14 +00:00 |
|
Miroslav Stampar
|
87abec16bd
|
probable fix for a bug reported by Prashant Jadhav
|
2010-09-30 18:52:33 +00:00 |
|
Bernardo Damele
|
84778f0e6c
|
Minor fix, leave like this
|
2010-05-29 08:58:55 +00:00 |
|
Miroslav Stampar
|
d3e527aba3
|
minor update
|
2010-05-29 07:13:54 +00:00 |
|
Bernardo Damele
|
10521b68eb
|
Major bug fix in multipartpost and minor adjustments elsewhere
|
2010-05-28 23:12:20 +00:00 |
|
Bernardo Damele
|
a1b1f960cc
|
Finally fixed and adapted all code around to the new isWindowsDriveLetterPath() function
|
2010-04-23 16:34:20 +00:00 |
|
Miroslav Stampar
|
1bcec80e95
|
fix for that takeover bug Ethan Robish posted (Windows/PHP)
|
2010-04-22 10:31:33 +00:00 |
|
Bernardo Damele
|
156fdd96ef
|
Updated copyright
|
2010-03-03 15:26:27 +00:00 |
|
Bernardo Damele
|
2f452480b3
|
Minor bug fix in syntax
|
2010-03-01 14:40:18 +00:00 |
|
Bernardo Damele
|
694356821d
|
sqlmap does not save nor leave back in temporary folder any file named 'sqlmapRANDOM', only random names now, less suspicious
|
2010-02-26 13:13:50 +00:00 |
|
Miroslav Stampar
|
1f2a1bb24c
|
removed some redundant code
|
2010-02-26 12:36:41 +00:00 |
|
Miroslav Stampar
|
e4c34ff86c
|
changed default web server language behaviour
|
2010-02-25 16:55:02 +00:00 |
|
Miroslav Stampar
|
0913d700a8
|
important update regarding default directories
|
2010-02-25 15:22:41 +00:00 |
|
Miroslav Stampar
|
4a3fa69f9d
|
minor adjustment
|
2010-02-25 15:07:54 +00:00 |
|
Bernardo Damele
|
0df5b5fed9
|
Minor bug fix and code adjustments
|
2010-02-25 14:06:44 +00:00 |
|
Miroslav Stampar
|
24d3e24db0
|
more updates regarding --os-shell feature
|
2010-02-25 12:16:49 +00:00 |
|
Miroslav Stampar
|
b558712a47
|
more feature updates
|
2010-02-25 11:40:49 +00:00 |
|
Miroslav Stampar
|
15d1fcbb7f
|
now runcmd exe has random name too
|
2010-02-25 10:47:12 +00:00 |
|
Miroslav Stampar
|
2cafd5697b
|
new changes regarding --os-shell
|
2010-02-25 10:33:41 +00:00 |
|
Miroslav Stampar
|
858cb25975
|
update
|
2010-02-24 23:40:56 +00:00 |
|
Miroslav Stampar
|
2a07af2294
|
removed pdb tracing
|
2010-02-20 22:36:17 +00:00 |
|
Miroslav Stampar
|
0debc95ad4
|
some fixes
|
2010-02-20 22:31:54 +00:00 |
|