| 
							
							
								 Bernardo Damele | 3a8309c4b0 | Major bug fix to detect UNION query technique and various improvements to parsing and using of --union-char and --union-cols switches | 2011-05-10 15:34:54 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 22a1870c2c | adding some constraining to number of used threads on brute force switches together with a warning in case of connection exception(s) with --threads>1 | 2011-05-10 12:32:07 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 83fac3f6d9 | fix for proper MSSQL error chunking in some cases (not screwing output length toward lower values at chunk phase) | 2011-05-03 21:12:51 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e6f010734e | minor fix for cases when the retrieved output is safe encoded (like for --os-shell) | 2011-05-03 16:14:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 742b0ef76e | major improvement of ERROR data retrieval on MSSQL | 2011-05-03 13:25:20 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 9a4ae7d9e2 | More code refactoring of Backend class methods used | 2011-04-30 14:54:29 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | f56d135438 | Minor code restyling | 2011-04-30 13:20:05 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f88aa4b165 | implemented suppressResumeInfo mechanism (huge slowdown on large tables) | 2011-04-22 19:58:10 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | fbe5ba5394 | cosmetics | 2011-04-21 10:54:12 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 8d8fc2bbd8 | cosmetics | 2011-04-21 10:17:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e4d3190f41 | reverting back to NVARCHAR because of error technique | 2011-04-20 12:59:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3607f03a9e | fix of a minor typo | 2011-04-20 12:42:35 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1286cc0913 | now showing trimmed output in for of warning message (UNION and ERROR techniques affected) | 2011-04-20 12:41:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 4fadcf0615 | improvement for UNION/ERROR case | 2011-04-20 10:17:42 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 29ee760021 | improving time based data retrieval mechanism | 2011-04-17 07:24:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 88c76147e1 | removed few trailing whitespace lines | 2011-04-15 20:52:08 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3b6f9945ae | minor fix regarding report from nightman@email.de (...from time to time sqlmap lost the connection...) | 2011-04-15 14:15:29 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0387654166 | update of copyright string (until year) | 2011-04-15 12:33:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | bb99bd2fbe | one more commit related to the issue with displaying of garbled characters | 2011-04-14 09:43:36 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 04986be4b9 | update regarding safe character output together with a small fix for newlines | 2011-04-14 09:31:45 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d06ae9cd47 | implemented retrieved items info for partial union too | 2011-04-13 14:33:15 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f5f2201bbc | minor cosmetics for partial inband retrieval | 2011-04-13 11:25:42 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c193b896be | just in case update to prevent gibberish "retrieved: " outputs | 2011-04-12 23:07:50 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6012ab1c46 | better one for previous commit | 2011-04-10 21:52:08 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e6c50df4f9 | preventing case duplicates for --common-tables (as some DBMSes have case sensitive table names we can't just use them all with the same case) | 2011-04-10 21:38:08 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 277f16d6b3 | removing commented out debug print | 2011-04-08 22:44:05 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6fa2fd139c | implemented support for __pivotDumpTable on MSSQL as normal tables tend to not play well with normal TOP 1 ..NOT IN..ORDER BY mechanism if the argument for ORDER BY is not the unique one (returns only number of rows equal to the number of distinct values for that field) | 2011-04-08 15:17:57 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 228cc68747 | fix for those ugly DEBUG messages in brute mode | 2011-04-08 11:02:21 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 5b21352656 | cosmeticados ;) | 2011-04-08 10:39:07 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e33a48d40f | minor refactoring | 2011-04-07 12:54:30 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | c6b9d89d31 | Accept [RANDNUM] as <char> in payloads.xml and handle it accordingly | 2011-04-07 11:10:35 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 8b14a9eaa7 | Minor code adjustments | 2011-04-06 14:40:45 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b327bbcd9b | minor fix (it was quite ... to have this check at the later stage) | 2011-04-06 08:39:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 557ed7d665 | minor fix for a invalid charset reported by Kirill | 2011-03-31 14:39:01 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | fed57282fc | Added one more warning message to show what's going on with ctrl+c | 2011-03-31 14:26:14 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 3948cd9e77 | Minor layout adjustments | 2011-03-31 14:13:53 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c5de903eab | minor improvement ("quick defense against substr fields") | 2011-03-31 09:35:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ce51326bff | quick fix | 2011-03-31 08:43:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0916117447 | improvement of error-based testing (no more sqlmap aborting on error-based payloads which happens very often on MySQL servers); also, minor improvement on brute forcing of column names | 2011-03-30 18:32:10 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b6af80bab3 | refactoring, cleanup and improvement | 2011-03-29 21:54:15 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 12f3024c8a | removing that boring message "reflective value found and filtered out" for headers case (we always include Uri header) | 2011-03-29 20:45:21 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d0861a00e2 | minor improvement | 2011-03-29 15:37:57 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1823c116bb | minor update for special cases of union testing results | 2011-03-28 21:45:38 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1119a85f39 | it's a must after all - partial union is specific and as there is no output for fetched value, we have to display something to the user. also, there is a bug fix (removed the leftover parseUnionPage) | 2011-03-25 21:31:26 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6c6133e8aa | revert of the last commit (i was doing some testing against a test case with lots of None(s) which drove me to the conclusion that we need that progress - in normal cases it's fine as it is) | 2011-03-25 20:46:37 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 737b4abf13 | this is a must for partial union. there are lots of cases with dumping of huge tables and user doesn't know a squirt if sqlmap is running or not (compromise is that this is only displayed if the verbose level is not touched by the user) | 2011-03-25 20:30:15 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 422967fbcd | just an minor update related to the last commit | 2011-03-25 12:21:53 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ea52d7acad | minor revisit of inference | 2011-03-24 20:10:40 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0f7bce5c66 | fixing a huge mess going on because of counting on error and union techniques | 2011-03-23 11:36:40 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7613134515 | it was a real pain in the ass to have SELECT COUNT(*) for all rows (it was processed by a limit logic) | 2011-03-22 12:37:05 +00:00 |  |