Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							60146481af
							
						
					 | 
					
						
						
							
							bug fix(es) (flags were used in place of count parameter in re.sub() calls)
						
						
						
						
						
					 | 
					
						2012-03-28 19:33:00 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							9433bbe26d
							
						
					 | 
					
						
						
							
							memory optimization for reflective removal mechanism (there was no need for \n\r in the first place as there was no re.S flag used - also, one re.sub "flags <-> count" bug fixed)
						
						
						
						
						
					 | 
					
						2012-03-28 19:27:12 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							7d131d1fb1
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2012-03-28 13:46:31 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							7fd64df167
							
						
					 | 
					
						
						
							
							minor code cleaning
						
						
						
						
						
					 | 
					
						2012-03-28 13:31:07 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							769b0d0ae7
							
						
					 | 
					
						
						
							
							more minor updates regarding data retrieval through DNS channel
						
						
						
						
						
					 | 
					
						2012-03-27 19:29:24 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							1b072f6415
							
						
					 | 
					
						
						
							
							laying foundation for DNS based data retrieval
						
						
						
						
						
					 | 
					
						2012-03-27 18:59:12 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							3abcd6910a
							
						
					 | 
					
						
						
							
							strange combination of "Set-Cookie" and interleaved pattern of True/False like responses can result in bypassing of the ABAB test
						
						
						
						
						
					 | 
					
						2012-03-22 00:06:50 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							e88687b1f0
							
						
					 | 
					
						
						
							
							revert of last commit (it would be faster for sure, but not sure if it's clever to do it by default regarding SQLi detection)
						
						
						
						
						
					 | 
					
						2012-03-21 23:15:59 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							524c1d38ad
							
						
					 | 
					
						
						
							
							making default redirect choice to NO (making fewer requests by default and in lots of cases clearer pages for comparison - original page vs redirect message)
						
						
						
						
						
					 | 
					
						2012-03-21 23:03:57 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							11132ba993
							
						
					 | 
					
						
						
							
							fix for a bug in reflection removal mechanism
						
						
						
						
						
					 | 
					
						2012-03-19 14:28:18 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							8e7d360ea2
							
						
					 | 
					
						
						
							
							cleaner refactoring regarding last commit
						
						
						
						
						
					 | 
					
						2012-03-19 12:03:25 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							401763b6f8
							
						
					 | 
					
						
						
							
							minor fix (it has to be level 1 array like it was with the previous re.findall mechanism)
						
						
						
						
						
					 | 
					
						2012-03-19 12:00:22 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							037db9b3b8
							
						
					 | 
					
						
						
							
							minor removal of older stuff
						
						
						
						
						
					 | 
					
						2012-03-19 09:38:27 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							da7f4eeffd
							
						
					 | 
					
						
						
							
							removing left over
						
						
						
						
						
					 | 
					
						2012-03-18 17:33:14 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							0fc4288a7c
							
						
					 | 
					
						
						
							
							modifying redirection code for only two choices
						
						
						
						
						
					 | 
					
						2012-03-18 17:27:08 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							c03d0e24fb
							
						
					 | 
					
						
						
							
							it must stay as is
						
						
						
						
						
					 | 
					
						2012-03-16 17:42:00 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							3505503a08
							
						
					 | 
					
						
						
							
							no need to return here
						
						
						
						
						
					 | 
					
						2012-03-16 17:30:16 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							942d9e4fa8
							
						
					 | 
					
						
						
							
							code cleanup
						
						
						
						
						
					 | 
					
						2012-03-16 17:27:24 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							a1c943fc79
							
						
					 | 
					
						
						
							
							Major bug fix to comparison algorithm with OR based boolean-based injections
						
						
						
						
						
					 | 
					
						2012-03-16 17:22:55 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							d66056fe39
							
						
					 | 
					
						
						
							
							one more related commit
						
						
						
						
						
					 | 
					
						2012-03-16 13:16:53 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							ac02a2d92c
							
						
					 | 
					
						
						
							
							minor fix
						
						
						
						
						
					 | 
					
						2012-03-16 13:14:14 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							cbdcbdd786
							
						
					 | 
					
						
						
							
							minor minor update
						
						
						
						
						
					 | 
					
						2012-03-16 11:18:18 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							b130a9e14e
							
						
					 | 
					
						
						
							
							minor fix (writing to HashDB on any interrupt)
						
						
						
						
						
					 | 
					
						2012-03-16 10:15:43 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							577caac4de
							
						
					 | 
					
						
						
							
							putting kb.negativeLogic setting to the safe place
						
						
						
						
						
					 | 
					
						2012-03-16 09:17:11 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							209e795369
							
						
					 | 
					
						
						
							
							minor just in case update
						
						
						
						
						
					 | 
					
						2012-03-16 09:02:17 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							adb5fff6b2
							
						
					 | 
					
						
						
							
							one more update related to the redirection mechanism
						
						
						
						
						
					 | 
					
						2012-03-15 20:17:40 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							7d313ac911
							
						
					 | 
					
						
						
							
							few more fixes for proper redirecting mechanism
						
						
						
						
						
					 | 
					
						2012-03-15 19:47:59 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							86c4650058
							
						
					 | 
					
						
						
							
							Minor bug fix - revert
						
						
						
						
						
					 | 
					
						2012-03-15 17:12:24 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							cc15373769
							
						
					 | 
					
						
						
							
							More explicit function name also getRatioValue parameter has nothing to do with comparison at this stage as far as I can see (that might have fixed another "bug", to be checked later)
						
						
						
						
						
					 | 
					
						2012-03-15 16:29:28 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							4520744b4d
							
						
					 | 
					
						
						
							
							second step toward negative logic support (ported to detection phase too) - works well with --string, --regexp and --code now
						
						
						
						
						
					 | 
					
						2012-03-15 16:25:26 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							ddd92476a8
							
						
					 | 
					
						
						
							
							minor fix
						
						
						
						
						
					 | 
					
						2012-03-15 15:58:25 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							19beb912fa
							
						
					 | 
					
						
						
							
							first step toward negative logic support
						
						
						
						
						
					 | 
					
						2012-03-15 15:52:12 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							8dd570057b
							
						
					 | 
					
						
						
							
							minor fix (double traffic log for -t in case of HTTP error)
						
						
						
						
						
					 | 
					
						2012-03-15 14:51:16 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							f7df755f37
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2012-03-15 12:55:22 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							3d39c6cb3b
							
						
					 | 
					
						
						
							
							some fixes here and there
						
						
						
						
						
					 | 
					
						2012-03-15 12:14:50 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							3d9b1599d1
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2012-03-15 11:45:32 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							91f1d6141f
							
						
					 | 
					
						
						
							
							minor fix
						
						
						
						
						
					 | 
					
						2012-03-15 11:24:55 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							a8c9a47092
							
						
					 | 
					
						
						
							
							redirect logic rewritten from scratch
						
						
						
						
						
					 | 
					
						2012-03-15 11:10:58 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							890bf708bc
							
						
					 | 
					
						
						
							
							Minor fixes to make --os-* switch work again against MySQL/Windows/ASP.NET (where stacked queries are supported)
						
						
						
						
						
					 | 
					
						2012-03-15 00:19:57 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							1e71b24dca
							
						
					 | 
					
						
						
							
							More info messages to prove xp_cmdshell (and temporary directory choosen) worked
						
						
						
						
						
					 | 
					
						2012-03-14 22:41:53 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							52a8b25ff4
							
						
					 | 
					
						
						
							
							minor fix
						
						
						
						
						
					 | 
					
						2012-03-14 14:31:41 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							ca0d068575
							
						
					 | 
					
						
						
							
							distinguishing NULL from BLANK
						
						
						
						
						
					 | 
					
						2012-03-14 13:52:23 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							e38b59a2ae
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2012-03-14 13:16:49 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							cee9ff7885
							
						
					 | 
					
						
						
							
							proper parsing of content in partial union technique
						
						
						
						
						
					 | 
					
						2012-03-14 11:23:30 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							61ad3b999a
							
						
					 | 
					
						
						
							
							fix for a crash with partial union and --hex
						
						
						
						
						
					 | 
					
						2012-03-14 10:31:24 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							a7fbc55748
							
						
					 | 
					
						
						
							
							grammar fix
						
						
						
						
						
					 | 
					
						2012-03-13 22:03:23 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							edfcddd3c3
							
						
					 | 
					
						
						
							
							minor fix for logging only cookies used by request (e.g. --load-cookies case)
						
						
						
						
						
					 | 
					
						2012-03-13 10:58:15 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							34b0935cb3
							
						
					 | 
					
						
						
							
							refactoring "echo 1" quick test for xp_cmdshell console output
						
						
						
						
						
					 | 
					
						2012-03-13 10:36:49 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							e827f41cdb
							
						
					 | 
					
						
						
							
							using pickle HIGHEST_PROTOCOL just in case
						
						
						
						
						
					 | 
					
						2012-03-13 09:35:37 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							e6c610abab
							
						
					 | 
					
						
						
							
							minor fix
						
						
						
						
						
					 | 
					
						2012-03-13 09:14:56 +00:00 | 
					
					
						
						
							
							
							
						
					 |