| 
							
							
								 Miroslav Stampar | 56638f9e95 | making --no-cast unhidden and renaming --negative-logic to --logical-negate to prevent confusion with stuff used in OR boolean based injection | 2012-03-30 10:50:01 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 637a8d8273 | improvement toward proper implementation of OR-based injection by usage of "negative logic" mechanism | 2012-03-29 14:33:27 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ce4c697bbd | disabling "negative logic" as it's not half done (it was "luckily" working for --string/--regex/--code but it was a sheer luck); removing "dirty fix" from checks.py; proof that this was not ready for the release is that there was not check for negative logic anywhere for anything more then --string/--regex/--code | 2012-03-29 13:39:12 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c9cac957bb | adding one more case for false positive check (Generic tests without any DBMS knowledge) | 2012-03-29 09:56:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3abcd6910a | strange combination of "Set-Cookie" and interleaved pattern of True/False like responses can result in bypassing of the ABAB test | 2012-03-22 00:06:50 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0fc4288a7c | modifying redirection code for only two choices | 2012-03-18 17:27:08 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 577caac4de | putting kb.negativeLogic setting to the safe place | 2012-03-16 09:17:11 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7d313ac911 | few more fixes for proper redirecting mechanism | 2012-03-15 19:47:59 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 4520744b4d | second step toward negative logic support (ported to detection phase too) - works well with --string, --regexp and --code now | 2012-03-15 16:25:26 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a7fbc55748 | grammar fix | 2012-03-13 22:03:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c878dd3e5a | doing a dummy test for --os-shell in case of xp_cmdshell | 2012-03-09 14:21:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a0b46963cb | minor fix for some special "unusable" cases (seen on Access/ODBC/Linux setup) | 2012-03-09 10:28:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0ead1fd87e | minor update | 2012-03-05 09:42:52 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1ec56f93ec | minor update | 2012-03-01 10:10:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f142c0f782 | minor update | 2012-02-28 14:04:13 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 22b3fa0749 | minor update | 2012-02-27 15:28:36 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a9bf0297f6 | moving injection data to HashDB | 2012-02-27 13:44:07 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f94b91ad87 | added helper function for HashDB data storing/retrieval | 2012-02-24 13:07:20 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6e54cb171f | minor code restyling | 2012-02-22 15:53:36 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b3bd4144f5 | removing of unused imports together with some general code refactoring | 2012-02-22 10:40:11 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 386e98a0e3 | using UNION SELECT for where=..NEGATIVE | 2012-02-22 09:41:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 844fc8addb | minor cleanup | 2012-02-16 10:19:36 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 23cc8b6974 | minor fix for special cases when parameter value contains html encoded characters | 2012-02-14 14:08:10 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2604e73d88 | minor change in workflow | 2012-02-13 11:18:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 96f589fc89 | minor fix | 2012-02-12 19:22:33 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 249cb48b0b | minor fix | 2012-02-10 15:59:11 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6be95194a7 | matter of concision | 2012-02-10 15:37:43 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | eab7a54e03 | cosmetics | 2012-02-10 15:34:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 92590d0d59 | minor fix | 2012-02-10 15:26:55 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e36e9de57e | minor update by request | 2012-02-10 15:12:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 11af0b1bbc | minor fix | 2012-02-07 11:16:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8405ef59ac | some estetic updates | 2012-02-01 14:49:42 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 23117e72ca | minor improvement | 2012-01-13 20:56:06 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 95f89ab63a | updating copyright date | 2012-01-11 14:59:46 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1d0b43b1a2 | implemented mechanism for merging cookies by request | 2012-01-11 14:28:08 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1f085a0241 | now [SLEEPTIME] is changeable properly in vivo | 2012-01-05 14:45:05 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 94d43a4135 | minor bug fix | 2011-12-30 14:20:06 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 22c3fe49bb | some refactoring | 2011-12-28 13:50:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f622995a29 | compatibility with partial union and error technique resumed data | 2011-12-22 12:20:21 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6f8d8a15aa | minor update | 2011-12-22 11:55:02 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 95cd9e2af3 | adding support for scanning Host header values (-p host) | 2011-12-20 12:52:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c57941c102 | minor beautification | 2011-12-15 23:33:44 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 27d244b326 | minor update | 2011-12-15 23:29:11 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 563c0c1066 | adding switch --tor-type | 2011-12-15 23:19:55 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0f5d48ff20 | minor update | 2011-12-05 09:25:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 872a73f631 | minor refactoring | 2011-11-29 19:17:07 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2842c13d75 | minor update | 2011-11-29 16:59:06 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2ed3efba12 | speed optimization and bug fix (kb.absFilePaths were not stored previously; also, they are now extracted only in heuristic phase) | 2011-11-22 08:39:13 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | eee03871d7 | minor refactoring | 2011-11-21 21:31:08 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 49fddaf668 | minor update (for cases with 404 original page - e.g. time based injections in some cases) | 2011-11-20 23:11:18 +00:00 |  |