Miroslav Stampar
|
2e5c11e427
|
Closes #1163
|
2015-02-13 10:59:03 +01:00 |
|
Miroslav Stampar
|
2e9bf47703
|
Heuristic check for WAF/IDS/IPS is now prone to tamper functions (Issue #1145)
|
2015-01-30 22:12:35 +01:00 |
|
Miroslav Stampar
|
b7cfaa6ca5
|
Minor style update
|
2015-01-22 08:55:37 +01:00 |
|
Miroslav Stampar
|
a603002acd
|
Adding a choice to automatically turn on --identify-waf if protection has been detected
|
2015-01-20 09:38:18 +01:00 |
|
Miroslav Stampar
|
45bdefd29b
|
Update of copyright
|
2015-01-06 15:02:16 +01:00 |
|
Miroslav Stampar
|
6fc41ca940
|
Heuristically checking for WAF/IDS/IPS by default
|
2015-01-06 14:01:47 +01:00 |
|
Miroslav Stampar
|
e6de92ce88
|
Minor patch (unicode related)
|
2014-12-15 13:36:08 +01:00 |
|
Miroslav Stampar
|
1e06e7c386
|
Adding a debug message during name resolution
|
2014-12-11 13:29:26 +01:00 |
|
Miroslav Stampar
|
9b32e69f26
|
Adding new WAF script (UrlScan)
|
2014-12-04 10:06:15 +01:00 |
|
Miroslav Stampar
|
f0802c6fb9
|
Update for an Issue #431
|
2014-11-21 11:20:54 +01:00 |
|
Miroslav Stampar
|
c6a8feea8a
|
Fix for an Issue #831
|
2014-10-07 12:00:11 +02:00 |
|
Miroslav Stampar
|
f67a38dba9
|
Minor adjustment
|
2014-10-01 13:42:10 +02:00 |
|
Miroslav Stampar
|
a9454fbb43
|
Minor commit related to the last one (bypassing DBMS error trimming problem)
|
2014-10-01 13:35:20 +02:00 |
|
Miroslav Stampar
|
8c9014c39f
|
Adding a dummy (auxiliary) XSS check
|
2014-10-01 13:31:48 +02:00 |
|
Miroslav Stampar
|
bfc8ab0e35
|
Language update
|
2014-09-08 14:48:31 +02:00 |
|
Miroslav Stampar
|
53d0d5bf8b
|
Minor update (adding a warning message about potential dropping of requests because of protection mechanisms involved)
|
2014-09-08 14:33:13 +02:00 |
|
Miroslav Stampar
|
20ff402103
|
Minor patch
|
2014-08-30 22:04:55 +02:00 |
|
Miroslav Stampar
|
1a9a331422
|
Bug fix (proper extending of tests when dbms is known)
|
2014-08-30 21:34:23 +02:00 |
|
Miroslav Stampar
|
834f8e18c8
|
Minor patch for an Issue #802
|
2014-08-28 00:45:57 +02:00 |
|
Miroslav Stampar
|
b77d8d617b
|
Minor patch for an Issue #800
|
2014-08-28 00:31:49 +02:00 |
|
Miroslav Stampar
|
7828f61642
|
Minor style update
|
2014-08-20 13:35:41 +02:00 |
|
Miroslav Stampar
|
6795b51c7e
|
Another minor update
|
2014-08-20 01:59:30 +02:00 |
|
Miroslav Stampar
|
d08c1b7c04
|
Minor update
|
2014-08-20 01:45:42 +02:00 |
|
Miroslav Stampar
|
ebc964267f
|
Better reporting on filtered-chars cases
|
2014-08-20 01:11:26 +02:00 |
|
Miroslav Stampar
|
b31e141012
|
Fix for an Issue #772
|
2014-07-29 14:37:48 +02:00 |
|
Miroslav Stampar
|
0eb5fb1e5a
|
Update for an Issue #757
|
2014-07-19 23:02:14 +02:00 |
|
Miroslav Stampar
|
2a88436417
|
Patch for an Issue #724
|
2014-06-16 09:51:24 +02:00 |
|
Miroslav Stampar
|
106102bd3c
|
Fix for an Issue #648
|
2014-03-21 20:28:29 +01:00 |
|
Miroslav Stampar
|
3b47418a1d
|
Fix for an Issue #640
|
2014-03-14 22:20:20 +01:00 |
|
Miroslav Stampar
|
2ffdee5733
|
Bug fix for PAYLOAD.WHERE.REPLACE payloads containing custom injection marker ([ORIGVALUE] was screwed)
|
2014-02-26 11:41:48 +01:00 |
|
Miroslav Stampar
|
edc8ef9d5b
|
Patch for an Issue #611 (original page used in case of tamper functions was wrong - e.g. if --tamper=base64encode was used)
|
2014-02-25 13:48:34 +01:00 |
|
Miroslav Stampar
|
2a423d61ef
|
Raising number of requests for false positive testing in case of higher levels
|
2014-02-23 19:40:01 +01:00 |
|
Miroslav Stampar
|
fe0ff6e679
|
Changing 'is injectable' to 'seems to be injectable' for boolean and time-based blind injection cases - for false positive cases
|
2014-02-09 17:50:16 +01:00 |
|
Miroslav Stampar
|
f97fcb7bb3
|
Adding a switch --invalid-string
|
2014-01-23 21:56:06 +01:00 |
|
Miroslav Stampar
|
f88f6dcd7e
|
Changing --invalid-bignum from float producing to int producing
|
2014-01-23 09:07:25 +01:00 |
|
Bernardo Damele
|
43a4e85749
|
updated copyright
|
2014-01-13 17:24:49 +00:00 |
|
Miroslav Stampar
|
6c80f2903b
|
Patch for an Issue #564
|
2013-12-27 11:02:59 +01:00 |
|
Miroslav Stampar
|
7ed05f01b3
|
Minor update
|
2013-10-27 00:24:57 +02:00 |
|
Miroslav Stampar
|
334c698d53
|
Adding change verbosity level in testing phase when Ctrl+C pressed
|
2013-10-17 16:54:53 +02:00 |
|
Miroslav Stampar
|
2dc570d7a8
|
Minor patch (for ORDER BY 'col' cases)
|
2013-10-10 23:08:20 +02:00 |
|
Miroslav Stampar
|
369006ca73
|
Bug fix
|
2013-10-07 12:54:25 +02:00 |
|
Miroslav Stampar
|
0cf2bdeb1c
|
Minor language update
|
2013-08-22 11:11:30 +02:00 |
|
Miroslav Stampar
|
941b2387c0
|
Minor fix
|
2013-07-31 09:22:45 +02:00 |
|
stamparm
|
e6f71c2130
|
Making 10% less requests in futile higher level/risk runs (using static template payloads for where==NEGATIVE)
|
2013-07-15 16:24:49 +02:00 |
|
stamparm
|
c9d3974205
|
Minor fix (templatePayload had duplicate string patterns for where==NEGATIVE)
|
2013-07-15 13:54:02 +02:00 |
|
stamparm
|
ac2d40e259
|
Revert of last commit (there is a chance that that big integer value is really valid :)
|
2013-07-15 13:34:38 +02:00 |
|
stamparm
|
a097ee1505
|
Switching --invalid-bignum to a pure integer constant (more generic - more statements require pure integer constant)
|
2013-07-15 13:31:56 +02:00 |
|
stamparm
|
d7c0805e7c
|
Removing leftover
|
2013-07-08 12:45:02 +02:00 |
|
stamparm
|
a548eb5c70
|
Minor text update
|
2013-07-08 12:44:14 +02:00 |
|
stamparm
|
d0e79a4d15
|
Minor text update
|
2013-07-08 12:38:36 +02:00 |
|