Bernardo Damele
|
35fb50a6ee
|
Major bug fix
|
2011-01-17 22:56:04 +00:00 |
|
Bernardo Damele
|
47565f9459
|
Minor code refactoring
|
2011-01-17 21:13:59 +00:00 |
|
Miroslav Stampar
|
041abb56e2
|
you can't believe how much man can learn when having good testing points
|
2011-01-17 13:59:22 +00:00 |
|
Miroslav Stampar
|
d225c5c9aa
|
was wrong about this one (just now tested on a real site)
|
2011-01-17 11:00:09 +00:00 |
|
Miroslav Stampar
|
ac0b5e6dbc
|
proper way to handle this (console output has totally different encoding than the page one)
|
2011-01-17 10:27:36 +00:00 |
|
Miroslav Stampar
|
34d13be0d3
|
minor update regarding default page encoding
|
2011-01-17 10:23:37 +00:00 |
|
Miroslav Stampar
|
5c857779c1
|
important fix for unicode based character inference
|
2011-01-17 10:15:19 +00:00 |
|
Miroslav Stampar
|
0fcca671bd
|
information update regarding common password suffixes
|
2011-01-17 09:28:25 +00:00 |
|
Miroslav Stampar
|
a835f233ac
|
fix for a bug reported by buawig@gmail.com (AttributeError: 'module' object has no attribute 'set_completer')
|
2011-01-17 00:17:31 +00:00 |
|
Miroslav Stampar
|
2041361695
|
minor cosmetics
|
2011-01-16 23:20:52 +00:00 |
|
Miroslav Stampar
|
e2c821eb81
|
minor cosmetics
|
2011-01-16 22:35:54 +00:00 |
|
Miroslav Stampar
|
e881465a9f
|
minor improvement
|
2011-01-16 20:55:07 +00:00 |
|
Miroslav Stampar
|
a6516798c0
|
proper fix for that previous "stacked" fix (that one screwed other injection types)
|
2011-01-16 19:25:10 +00:00 |
|
Miroslav Stampar
|
5476a8a27e
|
russian sites are great for testing :)
|
2011-01-16 19:00:19 +00:00 |
|
Miroslav Stampar
|
19dcaeaabf
|
fix for "Payload: id=1 ; SELECT PG_SLEEP(5);--" (blank space was added in case when prefixes weren't stated)
|
2011-01-16 18:25:18 +00:00 |
|
Miroslav Stampar
|
30d6791968
|
update regarding time based data retrieval
|
2011-01-16 17:52:42 +00:00 |
|
Miroslav Stampar
|
2001bad7e1
|
automatic adjustment of timeSec for delayed queries
|
2011-01-16 12:04:32 +00:00 |
|
Miroslav Stampar
|
71391874eb
|
slightly faster and thread safer inference
|
2011-01-16 10:52:42 +00:00 |
|
Bernardo Damele
|
0fc4ebdc1b
|
Major bug fix.
Minor code refactoring.
|
2011-01-16 01:17:09 +00:00 |
|
Miroslav Stampar
|
29ea0950b6
|
now False is also affected (along with None and "")
|
2011-01-15 23:43:26 +00:00 |
|
Bernardo Damele
|
558f3894f4
|
Minor improvement
|
2011-01-15 23:20:52 +00:00 |
|
Bernardo Damele
|
d3a28124b1
|
More code cleanup
|
2011-01-15 23:11:36 +00:00 |
|
Miroslav Stampar
|
3873d204bb
|
important update for dictionary attack
|
2011-01-15 15:56:11 +00:00 |
|
Miroslav Stampar
|
e17ac5fdca
|
update
|
2011-01-15 15:14:22 +00:00 |
|
Miroslav Stampar
|
5bdb50c224
|
code review part 3
|
2011-01-15 13:15:10 +00:00 |
|
Miroslav Stampar
|
1fa8f0cba7
|
code reviewing part 2
|
2011-01-15 12:53:40 +00:00 |
|
Miroslav Stampar
|
6a0e0cde3c
|
code review of modules in lib/core directory
|
2011-01-15 12:13:45 +00:00 |
|
Miroslav Stampar
|
daf5662eab
|
update
|
2011-01-14 15:33:49 +00:00 |
|
Bernardo Damele
|
1cfd6a6b9d
|
Code cleanup
|
2011-01-14 15:16:34 +00:00 |
|
Miroslav Stampar
|
08f7e20c51
|
minor code refactoring
|
2011-01-14 14:55:59 +00:00 |
|
Miroslav Stampar
|
fb9d7cdfaa
|
refactoring, code clearing and removal of obsolete switch --longest-common
|
2011-01-14 14:37:03 +00:00 |
|
Bernardo Damele
|
534f51f9fc
|
Minor bug fix
|
2011-01-14 14:20:28 +00:00 |
|
Bernardo Damele
|
3c95d71ea5
|
Minor bug fix - restored of so called kb.misc.testedDbms (now kb.misc.fpDbms) to force the DBMS (only) during the fingerprint phase
|
2011-01-14 11:55:20 +00:00 |
|
Bernardo Damele
|
7d9fd5a7b7
|
Minor bug fix
|
2011-01-14 09:49:14 +00:00 |
|
Miroslav Stampar
|
676b95b30a
|
minor code refactoring
|
2011-01-14 09:44:56 +00:00 |
|
Bernardo Damele
|
f8c04ce020
|
Minor bug fix
|
2011-01-13 20:59:13 +00:00 |
|
Bernardo Damele
|
2ac8debea0
|
Major code refactoring - moved to one location only (getIdentifiedDBMS() in common.py) the retrieval of identified/fingerprinted DBMS.
Minor bug fixes thanks to previous refactoring too.
|
2011-01-13 17:36:54 +00:00 |
|
Miroslav Stampar
|
b0fdbdb13b
|
minor update
|
2011-01-13 15:15:56 +00:00 |
|
Bernardo Damele
|
877ea31521
|
Verbose docstring
|
2011-01-13 12:05:14 +00:00 |
|
Miroslav Stampar
|
ac5b49f555
|
update
|
2011-01-13 11:24:03 +00:00 |
|
Bernardo Damele
|
af4ee81e62
|
Cosmetics
|
2011-01-13 11:23:07 +00:00 |
|
Miroslav Stampar
|
ece2eb31ca
|
minor update
|
2011-01-13 11:08:29 +00:00 |
|
Bernardo Damele
|
ca33728fbc
|
Minor fix to avoid query splitting/unpacking when the statement is EXISTS()
|
2011-01-13 10:00:40 +00:00 |
|
Bernardo Damele
|
be6e2d6a31
|
Important bug fix.
Minor code restyling.
|
2011-01-13 09:41:55 +00:00 |
|
Bernardo Damele
|
b3a0f38f3f
|
Minor code refactoring and added internal debug prints
|
2011-01-12 12:03:23 +00:00 |
|
Bernardo Damele
|
af9725214a
|
Properly deal with partial (single entry) UNION injections.
Got rid of kb.union*, now it's all stored/used from kb.injection.
Minor bug fix with where=2 detection phase.
|
2011-01-12 12:01:32 +00:00 |
|
Bernardo Damele
|
3cff42986f
|
Code cleanup
|
2011-01-12 01:17:04 +00:00 |
|
Bernardo Damele
|
8a67aea754
|
One more step to fully working UNION exploitation after merge into detection phase
|
2011-01-12 01:13:32 +00:00 |
|
Bernardo Damele
|
b5c6f7556f
|
Minor update
|
2011-01-12 00:53:48 +00:00 |
|
Bernardo Damele
|
8bdb7ec58c
|
Ahead with UNION exploitation after UNION test moved to detection phase - a lot to do yet.
|
2011-01-12 00:47:39 +00:00 |
|