| 
							
							
								 Miroslav Stampar | 61b960f65f | minor update related to the last one | 2011-05-26 22:05:10 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 45caadbd4a | important update - finally found what was causing headache for UNION payloads in noticeable number of cases | 2011-05-26 21:54:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 4f2c999146 | fix for a bug reported by mail@8dh.de (UnicodeDecodeError:  requestMsg += "\n%s" % requestHeaders) | 2011-05-26 13:47:20 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5369657cd5 | fix for cases with retrieved binary files (preventing difflib nagging around comparison) | 2011-05-25 20:54:30 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0072c3af8e | fix for a bug reported by aboynes@gmail.com (for elt in self.a) | 2011-05-24 15:03:21 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f774d8fea0 | proper Tor settings (reverted r3915 and implemented it the right way) | 2011-05-24 11:06:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 915c206e3d | minor fix for socks proxy issues | 2011-05-24 09:47:10 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ad25bcc2be | better way for dealing with relative paths | 2011-05-24 05:26:51 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a536bf210f | improved redirection mechanism | 2011-05-23 23:20:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 40971aca94 | fixing nasty bug caused by retrying counter | 2011-05-22 10:59:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 712e238f33 | another minor fix | 2011-05-22 10:29:25 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2795aeff34 | minor fix | 2011-05-22 10:27:45 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 806e898694 | no more CRITICAL drop outs in test mode - lots of reports were related to this | 2011-05-22 10:21:49 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9b2623514a | one bug fix for Host header (value should be without port number); one improvement for --tables - when no tables ask user if he wants to brute force them; one tweak - adding kb.ignoreTimeout for --tables | 2011-05-22 09:48:46 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2ea613b170 | type correction and adding global flag kb.ignoreTimeout which could be useful | 2011-05-22 08:24:13 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 27f0e73cc9 | refactoring of 'target' flag in connect.py | 2011-05-22 07:46:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 25fff8c135 | changes in handling --tor (using SOCKS instead of HTTP for handling Tor - more standard way; doesn't require proxy bundle; fixes problems with default proxy ports on Win/Linux) | 2011-05-21 11:46:57 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9e5856caf8 | improvement for recognition of scalar vs multiple-row commands | 2011-05-19 16:45:05 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cc07e5dc97 | added --charset option to force charset encoding of the retrieved data (e.g. when the backend collation is different than the current web page charset) as requested by devon.mitchell1988@yahoo.com | 2011-05-17 22:55:22 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ba1df457ab | fix for a charset euc_tw reported by devon.mitchell1988@yahoo.com | 2011-05-16 19:26:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 053c245114 | few minor fixes | 2011-05-13 09:56:12 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a7d7be5ce0 | bug fix ('Host' header was being set to the conf.hostname for all getPages causing problems in some cases when retrieved page was not coming from that same Host) | 2011-05-13 01:01:53 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0b2da2f9f5 | minor beautification for --tor switch | 2011-05-12 05:46:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1dea609019 | fix for a bug reported by David (UnicodeDecodeError: url = url + '?' + query) | 2011-05-10 12:51:37 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a64407d9db | minor bug fix for multithreading and lots of connection retries | 2011-05-10 12:40:01 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 22a1870c2c | adding some constraining to number of used threads on brute force switches together with a warning in case of connection exception(s) with --threads>1 | 2011-05-10 12:32:07 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b324b99f6e | minor update of warning message | 2011-05-04 10:41:08 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1e6c2fea74 | update regarding warning for --random-agent during connection timeout in connection test phase | 2011-05-03 10:05:42 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f8c3086d15 | minor minor update | 2011-05-02 12:37:54 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 098f53d57a | patch for a problem reported by m.martin2311@yahoo.com (unknown charset 'is0-8859-1') | 2011-05-02 12:34:35 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 41fc9f9d54 | fix for an issue reported by andrew.gecse@upcmail.hu (unknown web page charset 'hungarian-iso-8859-2') | 2011-04-30 22:41:54 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 9a4ae7d9e2 | More code refactoring of Backend class methods used | 2011-04-30 14:54:29 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | f56d135438 | Minor code restyling | 2011-04-30 13:20:05 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b299912de4 | fix for a bug reported by ahmed@isecur1ty.org (UnicodeDecodeError: 'ascii' codec can't decode byte 0x84 in position 396: ordinal not in range(128)) for multipartpost | 2011-04-29 16:56:02 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6bb4dce3aa | minor refactoring | 2011-04-29 15:22:32 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | f3088079c0 | error message adjustment | 2011-04-21 22:31:02 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | d2f102f5a1 | cosmetics | 2011-04-21 20:21:37 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 930872cf3b | fix | 2011-04-21 14:20:09 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 11ecd16099 | cosmetics | 2011-04-21 10:08:38 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c84c4d835f | minor update | 2011-04-21 09:31:35 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 52c98afe93 | minor fix | 2011-04-20 08:38:46 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 24435a2c20 | implemented "break a tie" request by Andres Riancho | 2011-04-20 08:35:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3b133303bf | refactoring | 2011-04-19 22:54:13 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | fc90974940 | revert of last commit because of the situation in detection phase where payload is made at the starting point (can't change conf.timeSec in that phase) | 2011-04-19 14:50:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7abbd0c029 | removing a leftover | 2011-04-19 14:29:51 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 96b5fede5a | automatic increasing of time delay on lagging connections | 2011-04-19 14:28:51 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7a06af9a92 | added "lagging" critical message | 2011-04-19 10:37:20 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6463cad8c5 | minor update for SOAP payloads | 2011-04-18 14:29:52 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | da9ec67869 | removing leftover | 2011-04-18 13:43:22 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 354a2ce249 | 'chardet' heuristic engine added to the project | 2011-04-18 13:38:46 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 4fa00121e4 | that CONSTANT_RATIO was a pure black magic for dynamic pages. now we have better injection detection workflow than before (False, True, False) and it was just a matter of time for removing this one | 2011-04-17 21:58:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a7366bf710 | SOAP refactoring | 2011-04-17 21:39:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5e70eac98c | fix for a "popular" typo 'iso-5889-1' reported by David Guimaraes | 2011-04-16 06:44:29 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0387654166 | update of copyright string (until year) | 2011-04-15 12:33:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 04986be4b9 | update regarding safe character output together with a small fix for newlines | 2011-04-14 09:31:45 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a883ce26b5 | fix for a bug reported by ToR (AttributeError: 'NoneType' object has no attribute 'redcode') | 2011-04-12 13:25:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 723a7447b2 | minor refactoring | 2011-04-10 07:16:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c714ac6421 | added support for handling binary data values (no more garbish chars) | 2011-04-09 23:13:16 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 83feb097ef | greater flexibility for --batch when default is None | 2011-04-08 22:29:50 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 228cc68747 | fix for those ugly DEBUG messages in brute mode | 2011-04-08 11:02:21 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 5b21352656 | cosmeticados ;) | 2011-04-08 10:39:07 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 265fa52600 | minor code cosmetics | 2011-04-04 18:24:16 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 018b6b9430 | fix for a charset encoding reported by Kirill | 2011-04-04 18:20:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e957c4400c | minor revisit of tampering script(s) functionality (urlencode one is removed as it's currently obsolete regarding the whole process of automatic urlencoding) | 2011-04-04 08:04:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 305115a68b | important improvement of data handling (POST data and header values) | 2011-04-03 15:02:52 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | c3b54cc222 | Cosmetics | 2011-04-01 16:40:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 557ed7d665 | minor fix for a invalid charset reported by Kirill | 2011-03-31 14:39:01 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | dd01d66f13 | proper update regarding last commit | 2011-03-29 22:10:08 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 850328df6c | minor cosmetics | 2011-03-29 22:03:48 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9f707febf5 | minor update | 2011-03-29 15:43:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d28ca5809b | adding support for meta HTML header 'refresh' - popular one amongst login pages (stumbled when tested blind injections on Mutillidae login page) | 2011-03-29 14:16:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ae53ad4c30 | making an update for special case of timed out response | 2011-03-28 21:05:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 762397854e | fix for a bug reported by Kirill (unknown charset '8859-1') | 2011-03-24 09:27:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d79fae724c | minor refactoring | 2011-03-24 09:16:21 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cbfb10cbd1 | fix of a minor bug reported by syssecurity7@googlemail.com (missing iso-8858...) | 2011-03-21 16:43:46 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b53c9a2599 | minor fix and some refactoring | 2011-03-18 00:24:02 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 9526f0c4c2 | Minor layout adjustments | 2011-03-17 12:35:40 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cbdd9e921e | minor cosmetics | 2011-03-17 12:23:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6607a240cf | added logging to redirecthandler | 2011-03-17 12:21:27 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9a513198dd | minor fix regarding last couple of commits | 2011-03-17 11:25:37 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | fbd0cfda29 | minor update toward the implementation of request from Santiago | 2011-03-17 06:39:05 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e64f225e65 | minor refactoring | 2011-03-11 20:16:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2fd3f0d7b2 | minor update (added comment) | 2011-03-11 20:07:52 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5eae525010 | this was bothering me for some time (POST and/or GET payloads needs to be urlencoded throughly) | 2011-03-11 19:57:44 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5c97f9a496 | improvement of url encoding technique (implemented failsafe routine for shortening too long GET queries) | 2011-03-09 09:36:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 154d947c62 | minor update | 2011-03-07 10:15:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3a1f5744be | minor update to make counting variable totally independent of the urllib2's self.retried | 2011-03-02 10:42:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a010386a23 | finally a proper fix for that annoying recursive bug | 2011-03-02 10:29:38 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9856cb71de | redo of the last commit with comments added | 2011-02-28 18:58:05 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ade31b2cb0 | removal of obsolete item | 2011-02-28 18:49:25 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 21041f8b90 | further reflective value handling improvement | 2011-02-27 17:43:41 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 60605b6e7c | Major bug fix to make --first and --last apply only to --dump's entries dump phase (in either of the blind SQL injection techs only) | 2011-02-27 12:14:13 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 63b8156c00 | some update (if header key is non-unicode comformant) | 2011-02-25 09:43:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | aa88361ab1 | incorporation of method for neutralization of reflective values | 2011-02-25 09:22:44 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 12ede1e5de | minor JIC (just-in-case) update | 2011-02-22 13:18:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3f8eadf4fe | minor refactoring | 2011-02-22 13:00:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | dcad5410fe | minor refactoring | 2011-02-22 12:54:22 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 17c39fe231 | fix for that non-HTML stuff | 2011-02-22 11:32:55 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0c57f2af0f | minor fix | 2011-02-20 12:20:44 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 60b05ff49f | Reflect new switch name | 2011-02-19 21:05:15 +00:00 |  |