| 
							
							
								 Miroslav Stampar | 7411052456 | minor update regarding last commit | 2011-01-05 12:09:57 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 042e3f76ba | bug fix for a bug reported by nightman (RuntimeError: maximum recursion depth exceeded) | 2011-01-05 11:36:40 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | aa81ed4033 | implementation of a feature suggested by pan@knownsec.com (usage of charset type from http-equiv attribute in case when charset is not defined in headers) | 2011-01-04 15:49:20 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | eb11f5b2e0 | minor update | 2011-01-04 13:07:12 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c1dc73d0a1 | minor, just in case update related to the previous commit | 2011-01-04 12:56:55 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 709a7d156b | fix for a bug reported by shaohua pan (UnicodeDecodeError: 'ascii' codec can't decode...) | 2011-01-04 12:51:51 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d288c6d6e3 | minor update | 2011-01-04 08:40:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0eabca9fd4 | update for a previous update (putting conf.dataEncoding in getUnicode wherever we know that data won't be 'touched' or 'used' in anyway related to the current web page - if not sure, just leave it as it is) | 2011-01-03 22:31:29 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 08ccbf2c1e | important fix for a bug reported by x <deep_freeze@mail.ru> (along with normal fixes, getUnicode now uses kb.pageEncoding) | 2011-01-03 22:02:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 07129371bf | bug fix for time based injections with keepalive (keepalive module has timeout argument which screwed tbMsg); also, bug fix for cases when remote hosts forcefully disconnects the user on some tests (instead of retrying and critically going out, continue with further tests) | 2011-01-03 13:04:20 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | da138c46c1 | added support for displaying HTTP error codes (particularly interesting ones are 403 and 406 which screw up data retrieval and DBMS fingerprinting badly) | 2011-01-02 07:37:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ef27fd5ea1 | there is a huge problem with urllib2 connections that sockets are left opened causing problems with lots of disposable connections used (like in --threads) (http://mail.python.org/pipermail/python-bugs-list/2007-January/036873.html, http://mail.python.org/pipermail/python-bugs-list/2007-January/036873.html) | 2011-01-01 15:20:29 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 281d124fa6 | minor bug fix | 2010-12-31 12:04:39 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d1f5c1d7b7 | now when we "decode page" based on a charset, sanitizeAsciiString only brings unneeded filtering | 2010-12-29 15:10:42 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 93838fb155 | "patch" for a problem reported by black zero (v = self._sslobj.write(data)...UnicodeError) | 2010-12-28 14:40:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c0423761e8 | minor update | 2010-12-27 18:27:42 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9fb0e0fc85 | resume of brute forced data is now available | 2010-12-27 14:17:20 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f2373121d0 | noticed little DoS behavior and lots of connections in netstat (best way to deal with zombie connections is to explicitly close them if not needed any more) | 2010-12-26 14:36:51 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 569e060aab | important improvement | 2010-12-26 13:20:52 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cd337d9f39 | minor fix | 2010-12-26 09:46:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 562a6440d1 | fix for a bug reported by nightman (same as http://bugs.python.org/issue8797) | 2010-12-26 09:33:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b472b96f92 | bug fix, refactoring and improved extractErrorMessage capabilities | 2010-12-25 10:16:20 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2c23a59ba5 | fix for one of those more complex bugs (comparison was returning None while original page and/or page template were already had already DBMS error inside) | 2010-12-24 12:13:48 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | aab14fa2d3 | minor refactoring/cosmetics | 2010-12-24 11:06:57 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a09716a701 | minor update | 2010-12-24 10:07:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d5eebb1cbf | fix for a fundamentally bad presumtion (ratio should be > 0.6 in stable pages), especially today when we have stuff like where=2; also, just imagine 500s which could just say something like FALSE, while on ratio level it would be far below 0.6 | 2010-12-24 09:49:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cb17e61f35 | bug fix (UnicodeDecodeError: 'ascii' codec can't decode byte 0xa9 in position 959) | 2010-12-24 02:54:26 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8470de7b76 | bug fix for boolean proxy when using time based payloads | 2010-12-23 23:46:08 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 017ea9e686 | update | 2010-12-23 14:06:22 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8fc60215ed | lol. this was a pesky bug. heuristic wasn't working on one mssql test site and i couldn't find why. at end the problem was that when the HTTP code was raised (like 500) no parseResponse was called. | 2010-12-22 19:12:46 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 250608660d | Minor bug fix to always show HTTP request and response when verbose is set accordingly to 4, 5 or 6 regardless of the HTTP response code (error or not) | 2010-12-22 13:41:36 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5be9c04e44 | update regarding Sybase syntax | 2010-12-22 10:39:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7a525f28d4 | cosmetics | 2010-12-21 15:26:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b2e7f9484d | minor tuning (2 techniques MAX per value used) | 2010-12-21 15:24:14 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 385e208f38 | code refactoring regarding standard output suppression and some threading issues | 2010-12-21 14:21:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6b37ddada4 | removed some blank trailing spaces (with extra/shutils/blanks.sh) | 2010-12-21 10:31:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d554460aec | minor fix | 2010-12-21 01:09:39 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 416755c0b7 | minor adjustments | 2010-12-21 00:25:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 29001a4fce | minor update | 2010-12-20 23:21:01 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8fd3e7ba1f | thread based data added | 2010-12-20 22:45:01 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5852bad963 | some refactoring | 2010-12-20 18:56:06 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c948bced61 | should solve the problem with timeout problems in time-based payloads | 2010-12-20 16:45:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | eaf8929085 | more minor updates | 2010-12-20 10:48:53 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | fe67d3827c | code refactoring and some fixes | 2010-12-18 09:51:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 108a96c6b4 | some fixes | 2010-12-17 21:45:20 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b4450c6ddd | added one more level of MSSQL version check (if first fails for some reason) | 2010-12-17 21:01:14 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 95b2c0803b | minor fix | 2010-12-15 20:51:29 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cda00c7501 | code refactoring | 2010-12-15 12:43:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3f34b06a24 | minor cosmetics | 2010-12-15 12:34:14 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 445cc3bf3c | minor cosmetics | 2010-12-15 12:15:43 +00:00 |  |