Bernardo Damele
|
3b5c5cc457
|
Minor possible bug fix
|
2010-10-20 21:49:05 +00:00 |
|
Bernardo Damele
|
f95098693f
|
Removed unused functions
|
2010-10-20 21:16:28 +00:00 |
|
Bernardo Damele
|
430bb7478f
|
Minor bug fix
|
2010-10-20 21:15:06 +00:00 |
|
Miroslav Stampar
|
34f70657ee
|
fix for NULL values
|
2010-10-20 10:29:18 +00:00 |
|
Miroslav Stampar
|
00449f1402
|
fix/upgrade/chicken soup
|
2010-10-20 09:54:17 +00:00 |
|
Miroslav Stampar
|
e24bff0497
|
nice refactoring
|
2010-10-20 09:46:57 +00:00 |
|
Miroslav Stampar
|
5d3cbec457
|
no more regex. web server independent.
|
2010-10-20 09:35:46 +00:00 |
|
Miroslav Stampar
|
934adb5e8d
|
code refactoring
|
2010-10-20 09:09:04 +00:00 |
|
Miroslav Stampar
|
b032fdbf74
|
added randInt to error injection vectors
|
2010-10-20 08:56:58 +00:00 |
|
Miroslav Stampar
|
dabbcf9e23
|
fix for that 'Subquery returns more than 1 row'
|
2010-10-20 08:50:05 +00:00 |
|
Miroslav Stampar
|
82f44989ce
|
update of error based injection and bug fix for --roles on MSSQL server
|
2010-10-20 06:40:33 +00:00 |
|
Bernardo Damele
|
0817d1b78d
|
Cosmetics
|
2010-10-19 23:09:30 +00:00 |
|
Miroslav Stampar
|
8776db872c
|
minor refactoring
|
2010-10-19 23:05:24 +00:00 |
|
Miroslav Stampar
|
1b376c99a6
|
removed temp dictionary and replaced with kb.misc
|
2010-10-19 23:00:19 +00:00 |
|
Bernardo Damele
|
813f44da16
|
Minor bug fix for MSSQL connector --tables option
|
2010-10-19 22:11:17 +00:00 |
|
Miroslav Stampar
|
7927e97007
|
update
|
2010-10-19 18:34:57 +00:00 |
|
Miroslav Stampar
|
415524bd5a
|
remove --error, now it's only --error-test (it needs to return True to be able to use it)
|
2010-10-19 18:34:14 +00:00 |
|
Miroslav Stampar
|
8d9201a3dc
|
minor update
|
2010-10-19 18:23:21 +00:00 |
|
Miroslav Stampar
|
4009ef385e
|
more update regarding error based injection support
|
2010-10-19 18:17:34 +00:00 |
|
Miroslav Stampar
|
b2e0b615f8
|
fix for that MySQL checking
|
2010-10-19 17:38:39 +00:00 |
|
Miroslav Stampar
|
34d7de1d46
|
cosmetics
|
2010-10-19 15:28:54 +00:00 |
|
Miroslav Stampar
|
d7622bb9cf
|
major fix for MySQL error based injections
|
2010-10-19 15:17:16 +00:00 |
|
Miroslav Stampar
|
80505de15b
|
now --users work on Oracle and Postgre (tested)
|
2010-10-19 14:56:57 +00:00 |
|
Miroslav Stampar
|
4bc541ec3c
|
error based update
|
2010-10-19 14:47:13 +00:00 |
|
Miroslav Stampar
|
d0ebe428da
|
i've left error flag
|
2010-10-19 14:12:34 +00:00 |
|
Miroslav Stampar
|
bf850af2d8
|
fix for Oracle error based query "space" problem
|
2010-10-19 14:10:09 +00:00 |
|
Miroslav Stampar
|
6a8b1046d4
|
first successfull run of error based sqlmap in history :). tested --banner, --current-user, --current-db on 4 major DBMSes. still hidden from users (turn on flag error in getValue() in inject.py)
|
2010-10-19 12:02:04 +00:00 |
|
Miroslav Stampar
|
ccda92536f
|
added header
|
2010-10-19 09:13:30 +00:00 |
|
Miroslav Stampar
|
264e0a6fda
|
added support for displaying revision number at unhandled exception message
|
2010-10-19 08:55:14 +00:00 |
|
Miroslav Stampar
|
9a7fd29d4f
|
using pushValue and popValue
|
2010-10-18 22:22:41 +00:00 |
|
Miroslav Stampar
|
a97319656c
|
optimization - now if DBMS was detected by error based HTML parser, then it's moved at the first place for testing
|
2010-10-18 21:47:11 +00:00 |
|
Miroslav Stampar
|
729156e91c
|
proper fix
|
2010-10-18 21:39:46 +00:00 |
|
Miroslav Stampar
|
3d5494845c
|
minor bug fix
|
2010-10-18 21:32:50 +00:00 |
|
Miroslav Stampar
|
8b8fff41fe
|
cosmetics (adding html parsed DBMS) regarding heuristic check
|
2010-10-18 12:11:16 +00:00 |
|
Bernardo Damele
|
1d74036ee3
|
Minor cosmetic fixes
|
2010-10-18 11:34:53 +00:00 |
|
Bernardo Damele
|
36bc410333
|
Minor bug fix
|
2010-10-18 09:50:23 +00:00 |
|
Miroslav Stampar
|
6b70dadfb2
|
minor cosmetics
|
2010-10-18 09:09:22 +00:00 |
|
Miroslav Stampar
|
149837ebf5
|
added the same for proxy authorization header
|
2010-10-18 09:02:56 +00:00 |
|
Miroslav Stampar
|
aaebb4336e
|
fix for Bug #202
|
2010-10-18 08:54:08 +00:00 |
|
Bernardo Damele
|
683184cc8f
|
Minor refactoring
|
2010-10-17 21:06:52 +00:00 |
|
Bernardo Damele
|
cd0fe8dde0
|
Updated sample configuration file and cmdline help
|
2010-10-17 00:07:53 +00:00 |
|
Bernardo Damele
|
64b9f94fcf
|
Renamed --common-prediction switch to --predict-output
|
2010-10-16 23:50:13 +00:00 |
|
Bernardo Damele
|
f54c134d22
|
Minor adjustment
|
2010-10-16 22:43:05 +00:00 |
|
Bernardo Damele
|
6211915da5
|
Cosmetic fix
|
2010-10-16 22:31:16 +00:00 |
|
Bernardo Damele
|
7b71262de6
|
Cosmetic fix
|
2010-10-16 22:07:29 +00:00 |
|
Bernardo Damele
|
a2997a6dce
|
Minor bug fix to --tamper
|
2010-10-16 21:55:34 +00:00 |
|
Bernardo Damele
|
2129935e06
|
Split character for tamper scripts (--tamper option) is now comma, not semi-colon.
Minor enhancement
|
2010-10-16 21:52:16 +00:00 |
|
Bernardo Damele
|
2dae934a2b
|
Minor bug fixes, code refactoring and enhanced --tamper functionality
|
2010-10-16 21:33:15 +00:00 |
|
Bernardo Damele
|
84ed7f192a
|
Cosmetic fixes
|
2010-10-16 15:10:48 +00:00 |
|
Miroslav Stampar
|
1336b97c2c
|
removed --useBetween switch and added new tampering module ./tamper/between.py
|
2010-10-15 23:48:07 +00:00 |
|