Miroslav Stampar
|
9da8d55128
|
Implements #2557
|
2017-06-07 11:22:06 +02:00 |
|
Miroslav Stampar
|
eb098f6527
|
Fixes #2268
|
2016-11-09 12:27:10 +01:00 |
|
Miroslav Stampar
|
d605b3af3c
|
Revisiting banner xmls (Issue #2239)
|
2016-10-21 13:01:28 +02:00 |
|
Miroslav Stampar
|
ae465bbaf8
|
Minor revert of leftover
|
2016-10-11 01:09:30 +02:00 |
|
Miroslav Stampar
|
1b95dd2d9d
|
Fix for a bug reported privately by user (in some cases data has not been retrieved)
|
2016-10-11 01:07:31 +02:00 |
|
Miroslav Stampar
|
7f416846b7
|
Minor revisit of MsSQL error-based payloads
|
2016-10-06 23:50:32 +02:00 |
|
Miroslav Stampar
|
af1c9c7fb2
|
Related to the last commit
|
2016-10-04 23:48:09 +02:00 |
|
Miroslav Stampar
|
06b54ab134
|
Better choice of used table (INFORMATION_SCHEMA.CHARACTER_SETS can also be found in MsSQL and PgSQL; mysql.db can have permission problems)
|
2016-10-04 23:43:00 +02:00 |
|
Miroslav Stampar
|
fee5c7bd7c
|
Adding two new payloads and minor cosmetics
|
2016-10-04 23:39:18 +02:00 |
|
Miroslav Stampar
|
fb8afc6add
|
Adding a new payload (Oracle boolean based on error response)
|
2016-10-04 22:12:00 +02:00 |
|
Miroslav Stampar
|
3409953538
|
Revisiting default level 1 payloads (MySQL stacked queries are as frequent as double rainbows)
|
2016-09-29 12:59:51 +02:00 |
|
Miroslav Stampar
|
e77126e847
|
Removing obsolete functionality
|
2016-09-28 15:00:26 +02:00 |
|
Miroslav Stampar
|
d36b5c0a4b
|
Adding time-based blind (heavy query) payloads for Informix (Issue #552)
|
2016-09-28 10:30:09 +02:00 |
|
Miroslav Stampar
|
5079c42788
|
Adding Informix parameter replacement payloads (Issue #552)
|
2016-09-27 14:39:17 +02:00 |
|
Miroslav Stampar
|
bc7ab01066
|
Bug fix for generic parameter replacement (CASE)
|
2016-09-27 14:29:18 +02:00 |
|
Miroslav Stampar
|
978f56ad10
|
One more commit for #552 (--passwords)
|
2016-09-26 16:38:03 +02:00 |
|
Miroslav Stampar
|
aa0b97b562
|
Support for Informix --roles/--privileges (Issue #552)
|
2016-09-26 14:20:04 +02:00 |
|
Miroslav Stampar
|
484d9a4825
|
Implementation of --dump for Informix (Issue #552)
|
2016-09-23 17:21:48 +02:00 |
|
Miroslav Stampar
|
1b48ff223d
|
Adding initial support for Informix (Issue #552)
|
2016-09-23 12:33:27 +02:00 |
|
Miroslav Stampar
|
e519484230
|
Patching live-testing
|
2016-09-19 15:51:28 +02:00 |
|
Miroslav Stampar
|
c7f615f707
|
Renaming payload files (consistency with the rest of the project)
|
2016-07-17 00:21:16 +02:00 |
|
Miroslav Stampar
|
47ba7d4705
|
Minor update
|
2016-07-07 10:37:00 +02:00 |
|
Miroslav Stampar
|
292a28131d
|
Minor updates
|
2016-07-06 23:43:10 +02:00 |
|
Miroslav Stampar
|
2e775fbb75
|
(e.g.) ASPx MsSQL Chinese exception messages don't start with 'Exception: string'
|
2016-07-06 14:06:18 +02:00 |
|
Miroslav Stampar
|
e1d7641b8a
|
Good for different generic OleDB-alike connectors
|
2016-07-06 13:48:35 +02:00 |
|
Miroslav Stampar
|
7ad49f4185
|
Less problematic regexes for MsSQL errors
|
2016-07-05 09:32:08 +02:00 |
|
Miroslav Stampar
|
d9315830f9
|
Less problematic regex for MsSQL errors
|
2016-07-05 09:20:04 +02:00 |
|
Miroslav Stampar
|
2e2c62b6a7
|
More error regexes
|
2016-07-04 17:24:17 +02:00 |
|
Miroslav Stampar
|
53289b0234
|
Some more Informix error regexes
|
2016-07-04 10:03:36 +02:00 |
|
Miroslav Stampar
|
dd082ef79d
|
Minor update (new error regex for Informix)
|
2016-07-04 09:49:18 +02:00 |
|
Miroslav Stampar
|
74d0315fef
|
Update related to the last commit
|
2016-07-03 02:14:23 +02:00 |
|
Miroslav Stampar
|
3a9e36c52b
|
Reintroducing stacked queries removed in 79d08906a4 (good for WAF bypass)
|
2016-07-03 02:03:30 +02:00 |
|
Miroslav Stampar
|
65a0f15f69
|
Minor update (error regex for PHP's sqlsrv module)
|
2016-06-28 15:13:37 +02:00 |
|
Miroslav Stampar
|
98b77d32cc
|
Minor update
|
2016-06-27 11:16:41 +02:00 |
|
Miroslav Stampar
|
a4b60dc00f
|
New error regex for MsSQL
|
2016-06-26 00:40:54 +02:00 |
|
Miroslav Stampar
|
e9407cf791
|
Cleaning some garbage boundaries (it doesn't make any sense to use %00 as prefix)
|
2016-06-23 22:57:59 +02:00 |
|
Miroslav Stampar
|
cc313280af
|
Payload that never ever worked (now fixed)
|
2016-06-03 13:16:00 +02:00 |
|
Miroslav Stampar
|
f06ff42c58
|
This never worked. Not sure who incorporated it (WAITFOR DELAY can't go to SELECT/CASE)
|
2016-06-03 10:42:57 +02:00 |
|
Miroslav Stampar
|
4bc1cf4518
|
Vastly better patch for MsSQL payloads
|
2016-06-03 10:29:04 +02:00 |
|
Miroslav Stampar
|
d326965966
|
Reordering MySQL's error-based payloads (BIGINT and EXP have crazy bigger chunk lenghts)
|
2016-06-01 14:12:22 +02:00 |
|
Miroslav Stampar
|
f0b8fbb7fd
|
Implemented support for JSON_KEYS error-based SQLi (and tons of fixes for MySQL 'ORDER BY,GROUP BY' payloads)
|
2016-06-01 13:23:41 +02:00 |
|
Miroslav Stampar
|
7d1bdb35ca
|
Update of parsed versions
|
2016-06-01 10:44:08 +02:00 |
|
Miroslav Stampar
|
acc1277246
|
Minor update
|
2016-05-30 14:13:57 +02:00 |
|
Miroslav Stampar
|
b4ebbae354
|
New payload(s)
|
2016-05-30 11:25:24 +02:00 |
|
Miroslav Stampar
|
79d08906a4
|
Cleaning some redundant payload(s)
|
2016-05-27 23:59:48 +02:00 |
|
Miroslav Stampar
|
b9e5655e3c
|
Proper naming
|
2016-05-22 14:26:36 +02:00 |
|
Miroslav Stampar
|
3b74e99576
|
Minor update (support for MariaDB)
|
2016-05-11 15:47:35 +02:00 |
|
Miroslav Stampar
|
439fff684e
|
Minor update (MSSQL CONCAT payload)
|
2016-05-11 09:42:54 +02:00 |
|
Miroslav Stampar
|
5ed3cdc819
|
Minor update
|
2016-04-22 10:54:55 +02:00 |
|
Miroslav Stampar
|
a9526bda92
|
Minor patch
|
2016-04-11 22:38:44 +02:00 |
|