| 
							
							
								 Miroslav Stampar | 76eeba10e2 | unhiding --dns-domain switch | 2012-05-27 18:41:06 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 71ff081fde | minor update | 2012-05-27 09:11:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d335ec0c34 | turning back on time auto-adjustment mechanism (if turned off) after a threshold run of valid chars | 2012-05-26 07:00:26 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | db526bdbc0 | minor update (tainted values are not checked any more in multipleTargets mode) | 2012-05-25 09:52:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c394610740 | adding switch --skip-urlencode to skip URL encoding of POST data | 2012-05-24 23:30:33 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 86fdad2bfa | minor update | 2012-05-24 22:07:50 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | eed8d7eb5d | finalizing support for IPv6 | 2012-05-24 21:55:57 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b6d37d766a | minor update regarding IPv6 support | 2012-05-24 21:49:20 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 92286104e3 | minor just in case update | 2012-05-24 21:39:10 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3e9c57d177 | minor fix | 2012-05-24 21:36:35 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | be76928293 | minor fix | 2012-05-24 20:53:01 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2538e2d5b4 | fixing an issue with --file-read and ROW() MySQL payload (it's internal caching mechanism prevents error message if FROM part is not unique enough dumping only partial file content); minor refactoring | 2012-05-22 09:33:22 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2c057d5b3d | minor style update | 2012-05-21 22:40:52 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | bbfa4b6d5d | minor update | 2012-05-14 14:38:16 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 333f8057a5 | minor fix (when redirected path has non-ASCII char and conf.url is unicode) and bits along with pieces | 2012-05-14 14:06:43 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 595f69fa2c | minor language update | 2012-05-10 18:30:25 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 35f400b45b | minor language upgrade | 2012-05-10 18:25:12 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 80aedbe284 | adding a warning about --tor switch | 2012-05-10 18:17:32 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b81fe42d4b | turning off null connection on -o when --tor used (not compatible) | 2012-05-10 17:50:54 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | efdd86ddcc | minor just in case patch | 2012-05-10 14:22:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6367f59b98 | minor code refactoring | 2012-05-10 14:15:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1418ae9767 | little refactoring of parseUnionPage together with a patch for some special case | 2012-05-09 18:47:40 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 37f2709197 | making a generic solution for all "Generic comment"/MsAccess cases (it's the only DBMS which doesn't accept --, hence replacing generic comment with %00 for it) | 2012-05-09 09:08:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 64c241fe92 | limiting original UNION query results to only 1 result (potentially speeding things up in some cases) | 2012-05-08 13:45:53 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a121339395 | automatically writing uncracked hashes to a file for eventual further processing | 2012-05-08 10:46:05 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 96299d3d5d | minor refactoring | 2012-05-03 22:34:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cc28f6db6b | minor update | 2012-05-01 20:43:16 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 17efeaae7f | causing too much confusion among dummy users | 2012-05-01 09:04:11 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 694b14111f | skipping suffix if comment is used in agent.suffixQuery (and --suffix not explicitly set) | 2012-04-27 13:16:51 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6f67dc85ee | adding --invalid-bignum (Havij like bignum style for invalidating/negating values); renaming --logical-negate to --invalid-logical | 2012-04-25 20:29:07 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cec432f94d | minor update | 2012-04-23 14:43:59 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 697768c01a | adding --purge-output to be one of mandatory switches | 2012-04-23 14:42:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d57d5e4b2c | minor update | 2012-04-23 14:33:36 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1eecfb3dce | adding new file related to the last commit | 2012-04-23 14:25:16 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 095b25e1d1 | adding option '--purge' | 2012-04-23 14:24:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | be2da77bf8 | minor update | 2012-04-23 10:15:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 21c6b52198 | minor fix | 2012-04-23 10:11:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2b1b4c0742 | minor fix | 2012-04-18 10:01:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6ebb621228 | adding support for (custom) POST injection (marking injection point with '*' in conf.data) | 2012-04-17 14:23:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | efd27d7ade | minor renaming | 2012-04-17 08:41:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 601d118c68 | reverting back to UNION ALL scheme (UNION is doing another DISTINCT on data causing problems on some column types) | 2012-04-15 16:59:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 052d9455fe | warning user in cases of "User xyz already has more than 'max_user_connections' active connections" | 2012-04-12 09:44:54 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c7422546e1 | tiny update | 2012-04-11 23:01:38 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2bad73a981 | minor update | 2012-04-11 21:48:44 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e195de2093 | correcting comment on reflective removal function | 2012-04-11 21:41:48 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b45ae10da4 | minor fixes | 2012-04-11 21:36:37 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 627bfc589f | some more updates in reflective removal mechanism | 2012-04-11 21:26:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8b130f6497 | minor improvement for reflective values (when missing first part of payload like in error reports) | 2012-04-11 15:01:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 01bd5d0ab2 | some more updates for reflective mechanism | 2012-04-11 10:41:33 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2e92d8636e | improvement of reflective mechanism | 2012-04-11 08:58:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 60ca44e0cf | minor adjustment | 2012-04-11 08:35:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8541222080 | minor update | 2012-04-10 22:26:42 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9c2f244d47 | minor fix | 2012-04-10 22:20:53 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 119eec3598 | improving "boolean detection" by automatic recognition of convenient --string candidate | 2012-04-10 21:48:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8c6eb4faa9 | adding support for PgSQL DNS data exfiltration | 2012-04-07 14:06:11 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b2afa87e48 | reading page responses in chunks, trimming unnecessary content (especially for large table dumps in full inband cases) | 2012-04-06 08:42:36 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2223c884e5 | minor refactoring | 2012-04-05 12:55:26 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 02924eb345 | minor update | 2012-04-04 23:47:06 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | d106fb5184 | layout adjustments | 2012-04-04 12:27:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1b2cd44255 | proper fix | 2012-04-04 10:35:52 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7031ef8e00 | removing default values for referer and host from higher level/risk options | 2012-04-04 10:34:27 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b0787f193c | getting rid of obsolete getCompiledRegex (in newer versions of Python regexes are already cached) | 2012-04-03 14:34:15 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 33bb9c5f19 | much cleaner approach in that "flat" representation of retrieved items in union technique | 2012-04-03 13:56:11 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e05109812f | minor improvements regarding data retrieval through DNS channel | 2012-04-03 09:18:30 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2c28423cb8 | minor update | 2012-04-02 14:57:15 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1cd3c3f7af | further update of DNS data retrieval mechanism through SQLi | 2012-04-02 14:05:30 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1e01203562 | few just in case "patches" | 2012-04-02 12:58:10 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d908d078dd | minor fix | 2012-04-02 12:27:30 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | abffc39929 | minor update regarding DNS data retrieval task | 2012-04-02 12:22:40 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f7a664b120 | enablind DNS server for DNS data exfiltration | 2012-03-31 12:08:27 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8be9cd4ac4 | bug fix (on Linux machine when os.geteuid() returns an integer value !=0 it was then returned and interpreted as TRUE value) | 2012-03-31 10:22:50 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 56638f9e95 | making --no-cast unhidden and renaming --negative-logic to --logical-negate to prevent confusion with stuff used in OR boolean based injection | 2012-03-30 10:50:01 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 79c3d6f2aa | minor update | 2012-03-30 10:37:46 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 637a8d8273 | improvement toward proper implementation of OR-based injection by usage of "negative logic" mechanism | 2012-03-29 14:33:27 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 772ead8d03 | fixed support for error-based injection on MySQL 4.1 (help table a needs more than 2 items inside); also, fixed some border issues with reflective values | 2012-03-29 12:44:20 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 60146481af | bug fix(es) (flags were used in place of count parameter in re.sub() calls) | 2012-03-28 19:33:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9433bbe26d | memory optimization for reflective removal mechanism (there was no need for \n\r in the first place as there was no re.S flag used - also, one re.sub "flags <-> count" bug fixed) | 2012-03-28 19:27:12 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7fd64df167 | minor code cleaning | 2012-03-28 13:31:07 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 11132ba993 | fix for a bug in reflection removal mechanism | 2012-03-19 14:28:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0fc4288a7c | modifying redirection code for only two choices | 2012-03-18 17:27:08 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cbdcbdd786 | minor minor update | 2012-03-16 11:18:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | adb5fff6b2 | one more update related to the redirection mechanism | 2012-03-15 20:17:40 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 19beb912fa | first step toward negative logic support | 2012-03-15 15:52:12 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3d9b1599d1 | minor update | 2012-03-15 11:45:32 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a8c9a47092 | redirect logic rewritten from scratch | 2012-03-15 11:10:58 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 890bf708bc | Minor fixes to make --os-* switch work again against MySQL/Windows/ASP.NET (where stacked queries are supported) | 2012-03-15 00:19:57 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ca0d068575 | distinguishing NULL from BLANK | 2012-03-14 13:52:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 61ad3b999a | fix for a crash with partial union and --hex | 2012-03-14 10:31:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a7fbc55748 | grammar fix | 2012-03-13 22:03:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e827f41cdb | using pickle HIGHEST_PROTOCOL just in case | 2012-03-13 09:35:37 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cda8815634 | introducing safe deprecation mechanism for HashDB versioning | 2012-03-12 22:55:57 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6ed1b04bbe | minor update | 2012-03-12 13:27:07 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | c79807f5fb | Minor layout adjustments | 2012-03-08 15:11:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 775e424bf2 | bug fix for using --no-cast and --hex switches together | 2012-03-08 15:04:52 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 11c7cc5224 | minor temporary fix | 2012-03-08 11:08:43 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 98a3e43f53 | bug fix for writing raw pickled data into SQLite HashDB | 2012-03-08 10:57:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cd28eb6544 | minor update regarding --load-cookies | 2012-03-08 10:19:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2c87d061e9 | minor update | 2012-03-08 10:03:59 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b4cf8b05b3 | added switch --load-cookies | 2012-03-07 14:48:45 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 4cfea96471 | minor update | 2012-03-05 09:56:48 +00:00 |  |