Miroslav Stampar
|
0b24a80387
|
Patch related to the --hex and --technique=E (potential patch for #2837)
|
2017-12-20 14:51:15 +01:00 |
|
Miroslav Stampar
|
b9efdb2999
|
Fixes #2824
|
2017-12-11 11:26:09 +01:00 |
|
Miroslav Stampar
|
370884d07a
|
Fixes #2811
|
2017-12-04 14:59:05 +01:00 |
|
Miroslav Stampar
|
220dffbcfa
|
Couple of wording updates
|
2017-12-04 13:59:35 +01:00 |
|
Miroslav Stampar
|
7244e8e4e2
|
Minor patches
|
2017-12-04 13:24:51 +01:00 |
|
Miroslav Stampar
|
8735a49f63
|
Some more refactoring
|
2017-11-24 11:49:31 +01:00 |
|
Miroslav Stampar
|
b9e2e8b74d
|
Minor refactoring
|
2017-11-24 11:44:14 +01:00 |
|
Miroslav Stampar
|
58b87e4b6b
|
Some more refactoring
|
2017-11-08 15:58:23 +01:00 |
|
Miroslav Stampar
|
5c35aff22a
|
Minor refactoring
|
2017-11-08 15:47:12 +01:00 |
|
Miroslav Stampar
|
66d37112d1
|
If it works, don't touch. I touched
|
2017-10-31 11:38:09 +01:00 |
|
Miroslav Stampar
|
8c6b761044
|
Replacing doc/COPYING to LICENSE
|
2017-10-11 14:50:46 +02:00 |
|
Miroslav Stampar
|
b7db28a89b
|
Minor refactoring (unused imports)
|
2017-10-10 16:14:39 +02:00 |
|
Miroslav Stampar
|
62519eed04
|
Minor patch (breaking lines on longer outputs - 100%)
|
2017-09-26 13:18:37 +02:00 |
|
Miroslav Stampar
|
222fd856fa
|
Implementation for #2709
|
2017-09-25 11:32:40 +02:00 |
|
Miroslav Stampar
|
db94d24db1
|
Initial support for #2709 (more work to be done)
|
2017-09-21 14:35:24 +02:00 |
|
Miroslav Stampar
|
b4980778dd
|
Fixes #2577
|
2017-06-18 14:07:48 +02:00 |
|
Miroslav Stampar
|
9da8d55128
|
Implements #2557
|
2017-06-07 11:22:06 +02:00 |
|
Miroslav Stampar
|
996ad59126
|
Minor patch
|
2017-06-05 16:28:19 +02:00 |
|
Miroslav Stampar
|
4ce08dcfa3
|
Patch for an Issue #2536
|
2017-05-17 00:22:18 +02:00 |
|
Miroslav Stampar
|
1c5f01e2a2
|
Fixes #2487
|
2017-04-20 11:54:27 +02:00 |
|
Miroslav Stampar
|
ebbc68853d
|
Fixes #2496
|
2017-04-20 10:48:04 +02:00 |
|
Miroslav Stampar
|
2d05174545
|
Trivial update
|
2017-04-18 15:56:24 +02:00 |
|
Miroslav Stampar
|
5f2bb88037
|
Some code refactoring
|
2017-04-18 15:48:05 +02:00 |
|
Miroslav Stampar
|
7ebba5614a
|
Moving brute from techniques to utils
|
2017-04-18 13:53:41 +02:00 |
|
Miroslav Stampar
|
a702dafd03
|
Fixes #2481
|
2017-04-14 12:47:24 +02:00 |
|
Miroslav Stampar
|
9b3d229294
|
Fixes #2471
|
2017-04-10 19:21:22 +02:00 |
|
Miroslav Stampar
|
e506a390db
|
Minor patch (prevent message spamming of multiple union column possibilities)
|
2017-03-15 16:18:20 +01:00 |
|
Miroslav Stampar
|
b18444f215
|
Issue #2417 (most probably -> most likely)
|
2017-02-27 22:14:52 +01:00 |
|
Miroslav Stampar
|
7ea524800a
|
Taking couple of suggestions from #2417
|
2017-02-27 22:03:15 +01:00 |
|
Miroslav Stampar
|
55272f7a3b
|
New version preparation
|
2017-01-02 14:19:18 +01:00 |
|
Miroslav Stampar
|
edc6f47758
|
Some refactoring
|
2016-12-19 23:47:39 +01:00 |
|
Miroslav Stampar
|
7e6879ec41
|
Minor patch for #2272
|
2016-11-11 13:46:41 +01:00 |
|
Miroslav Stampar
|
0398cbdc76
|
Minor refactoring
|
2016-10-22 21:52:18 +02:00 |
|
Miroslav Stampar
|
9ff2dcf1c1
|
Fixes #2228
|
2016-10-15 00:16:53 +02:00 |
|
Miroslav Stampar
|
e5a758bdf4
|
Fixes #2192
|
2016-09-28 09:55:14 +02:00 |
|
Miroslav Stampar
|
212c1ec1f2
|
Couple of fixes and some testing stuff
|
2016-09-27 14:03:59 +02:00 |
|
Miroslav Stampar
|
7151df16f6
|
Adding extra validation step in case of boolean-based blind (e.g. if unexpected 500 occurs)
|
2016-09-27 11:21:12 +02:00 |
|
Miroslav Stampar
|
09617c8243
|
Introducing extra validation property in case of time-based SQLi (HTTP code) - Issue #1973
|
2016-09-27 10:20:36 +02:00 |
|
Miroslav Stampar
|
e10bb42597
|
Minor tweak
|
2016-09-22 10:22:48 +02:00 |
|
Miroslav Stampar
|
9902018cab
|
Implementation for an Issue #2172
|
2016-09-21 15:45:55 +02:00 |
|
Miroslav Stampar
|
9105f259cd
|
Fixes #2060 (ParseError has been added in Python 2.7)
|
2016-07-23 15:27:25 +02:00 |
|
Miroslav Stampar
|
7cca56edfa
|
Fixes #2052
|
2016-07-21 09:38:52 +02:00 |
|
Miroslav Stampar
|
ebb73b71fa
|
Fixes #2045
|
2016-07-20 16:49:27 +02:00 |
|
Miroslav Stampar
|
1e6191e3b1
|
Fixes #2026
|
2016-07-16 15:51:09 +02:00 |
|
Miroslav Stampar
|
ca67456dbe
|
Removing a debugging leftover (Issue #2025)
|
2016-07-14 23:39:44 +02:00 |
|
Miroslav Stampar
|
6df4d73b09
|
Implementation for an Issue #2025
|
2016-07-14 23:18:28 +02:00 |
|
Miroslav Stampar
|
5038d7a70a
|
Removing ugly boolean check results (0 or 1) in output of UNION and ERROR SQLi
|
2016-06-01 13:39:40 +02:00 |
|
Miroslav Stampar
|
510197c39e
|
Minor text update
|
2016-05-30 10:52:30 +02:00 |
|
Miroslav Stampar
|
3865b3a398
|
Minor improvement in case of technique E (when waiting for large entry - lots of chunks)
|
2016-05-25 12:50:53 +02:00 |
|
Miroslav Stampar
|
d6bcbbae1d
|
Minor patch for E technique to be more compatible with output of U technique
|
2016-05-25 12:42:15 +02:00 |
|
Miroslav Stampar
|
04b3aefc5d
|
Patch for special character output in U and E techniques
|
2016-05-25 12:24:36 +02:00 |
|
Miroslav Stampar
|
39fe96009f
|
Minor improvement (related to the last commit)
|
2016-05-24 16:20:39 +02:00 |
|
Miroslav Stampar
|
b475a38895
|
Better ORDER BY detection
|
2016-05-24 15:46:06 +02:00 |
|
Miroslav Stampar
|
f7cae68378
|
More formal language
|
2016-05-22 21:44:17 +02:00 |
|
Miroslav Stampar
|
0c5965c7b8
|
Minor patches
|
2016-04-19 13:13:37 +02:00 |
|
Miroslav Stampar
|
67ae620182
|
Another patch related to the #1752
|
2016-03-12 15:04:19 +01:00 |
|
Miroslav Stampar
|
13366aeb48
|
Fixes #1752
|
2016-03-12 12:26:30 +01:00 |
|
Miroslav Stampar
|
410df455ab
|
Minor consistency patch
|
2016-02-13 21:03:05 +01:00 |
|
Miroslav Stampar
|
e53e4dddf1
|
Minor patch
|
2016-01-10 23:12:46 +01:00 |
|
Miroslav Stampar
|
e519ed2e18
|
Another patch related to the #1655
|
2016-01-10 23:07:11 +01:00 |
|
Miroslav Stampar
|
8b01996adf
|
Patch related to the #1655
|
2016-01-10 22:59:40 +01:00 |
|
Miroslav Stampar
|
5908964db4
|
Another (better) patch for #1636
|
2016-01-09 17:32:19 +01:00 |
|
Miroslav Stampar
|
0f8a551227
|
Potential patch for #1636
|
2016-01-09 00:55:01 +01:00 |
|
Miroslav Stampar
|
e3650342bd
|
Fixes #1639
|
2016-01-08 11:47:12 +01:00 |
|
Miroslav Stampar
|
b427f6c03e
|
Minor bug fix
|
2016-01-08 10:52:02 +01:00 |
|
Miroslav Stampar
|
6f3511dcc3
|
Error chunk length bug fix (reported privately)
|
2016-01-08 10:45:31 +01:00 |
|
Miroslav Stampar
|
d0d676ccce
|
Update of copyright string
|
2016-01-06 00:06:12 +01:00 |
|
Miroslav Stampar
|
a18c69d78b
|
Fixes #1564
|
2015-11-25 10:21:32 +01:00 |
|
Miroslav Stampar
|
829351421f
|
Minor cosmetics
|
2015-11-25 10:12:07 +01:00 |
|
Miroslav Stampar
|
efe41fbdc7
|
Fixes #1547
|
2015-11-20 11:32:54 +01:00 |
|
Miroslav Stampar
|
4335ae8330
|
Patching previous commit
|
2015-11-16 16:59:54 +01:00 |
|
Miroslav Stampar
|
94639d11a3
|
Another update related to the #1539
|
2015-11-16 15:33:05 +01:00 |
|
Miroslav Stampar
|
d772e7e1d5
|
Fixes #1529
|
2015-11-11 16:07:11 +01:00 |
|
Miroslav Stampar
|
5198e4c816
|
Minor bug fix (based on private user report)
|
2015-11-04 15:04:38 +01:00 |
|
Miroslav Stampar
|
570562369b
|
Further fixes for sqlmap to work properly with HSQLDB (WebGoat)
|
2015-10-13 13:04:59 +02:00 |
|
Miroslav Stampar
|
ac467bc453
|
Fixes #1437
|
2015-09-28 09:54:41 +02:00 |
|
Miroslav Stampar
|
38541b021a
|
Implementing hidden switch '--force-threads' on request (to force multi-threading in time-based SQLi)
|
2015-09-26 00:09:17 +02:00 |
|
Miroslav Stampar
|
74294ae105
|
Bug fix for --common-tables in case of MsSQL/Sybase (safeSQLIdentificatorNaming already used)
|
2015-09-22 11:28:56 +02:00 |
|
Miroslav Stampar
|
a33b0454cd
|
Implementation for an Issue #1360
|
2015-08-26 15:26:16 +02:00 |
|
Miroslav Stampar
|
2c2f83f67b
|
Minor code consistency patch
|
2015-08-26 11:30:48 +02:00 |
|
Miroslav Stampar
|
023def3203
|
Fixes #1336
|
2015-08-16 23:47:11 +02:00 |
|
Miroslav Stampar
|
21e8182ac6
|
Fixes #1305
|
2015-07-18 17:01:34 +02:00 |
|
Miroslav Stampar
|
84ba3d45c1
|
Patch for an Issue #1238
|
2015-05-04 21:47:10 +02:00 |
|
Miroslav Stampar
|
45bdefd29b
|
Update of copyright
|
2015-01-06 15:02:16 +01:00 |
|
Miroslav Stampar
|
7b144f03ea
|
Fix for an Issue #1092
|
2015-01-05 01:31:06 +01:00 |
|
Miroslav Stampar
|
650dfe9526
|
Patch for an Issue #1018
|
2014-12-12 14:54:47 +01:00 |
|
Miroslav Stampar
|
d700e50b36
|
Minor update related to the Issue #993
|
2014-12-10 06:37:17 +01:00 |
|
Miroslav Stampar
|
a074efe75e
|
Minor improvement of error-based SQLi when trimmed output is detected (trying to reconstruct)
|
2014-11-05 10:46:11 +01:00 |
|
Miroslav Stampar
|
e81168af0f
|
Minor adjustment
|
2014-10-01 13:59:51 +02:00 |
|
Miroslav Stampar
|
77cb35dcf6
|
Fix for an Issue #804
|
2014-08-28 14:26:55 +02:00 |
|
Miroslav Stampar
|
fd36250026
|
Proper fix for an Issue #757
|
2014-08-26 23:36:04 +02:00 |
|
Miroslav Stampar
|
dcaad75a1e
|
Fix for an Issue #794
|
2014-08-22 15:08:05 +02:00 |
|
Miroslav Stampar
|
acb3b1d1fe
|
Bug fix for common table/column existence check
|
2014-08-21 00:12:19 +02:00 |
|
Miroslav Stampar
|
074b57804e
|
Minor style update
|
2014-08-21 00:03:46 +02:00 |
|
Miroslav Stampar
|
5d10bae31f
|
Removing trailing blank lines
|
2014-08-20 21:07:19 +02:00 |
|
Miroslav Stampar
|
c12e51173a
|
Minor style update
|
2014-08-20 00:28:33 +02:00 |
|
Miroslav Stampar
|
0fb576724e
|
Implementation for cases when there are multiple copies/variations of the same result(s) in response for partial UNION SQLi
|
2014-08-13 22:50:42 +02:00 |
|
Miroslav Stampar
|
cd1c100cc0
|
Another patch for an Issue #757
|
2014-07-14 21:10:45 +02:00 |
|
Miroslav Stampar
|
e66a81ab4e
|
Fix for an Issue #757
|
2014-07-11 16:24:57 +02:00 |
|
Miroslav Stampar
|
33b6d189cd
|
Bug fix for some cases (in cases of working where=ORIGINAL, workflow switched to where=NEGATIVE because of false assumptions that it would be better than ORIGINAL; this kind of behaviour caused reported problems)
|
2014-07-07 22:22:56 +02:00 |
|
Miroslav Stampar
|
8e660e6911
|
Minor fix
|
2014-06-27 14:14:29 +02:00 |
|
Miroslav Stampar
|
4e8b41b869
|
Patch for an Issue #688
|
2014-05-13 00:50:36 +02:00 |
|
Miroslav Stampar
|
2f8846caec
|
Fix for an Issue #636
|
2014-03-11 21:11:51 +01:00 |
|
Miroslav Stampar
|
d1a6a775f1
|
Patch for an Issue #636
|
2014-03-11 21:00:15 +01:00 |
|
Bernardo Damele
|
43a4e85749
|
updated copyright
|
2014-01-13 17:24:49 +00:00 |
|
Miroslav Stampar
|
7718edac9b
|
Fix for an Issue #570
|
2013-12-27 09:40:33 +01:00 |
|
Miroslav Stampar
|
ab64d385d6
|
Bug fix (stacked queries as in PgSQL and MsSQL DNS tunneling queries MUST end with the comment - not the recognized underlying technique's suffix)
|
2013-12-25 22:18:57 +01:00 |
|
Miroslav Stampar
|
953b5815d8
|
Implementation for an Issue #496
|
2013-07-31 21:15:03 +02:00 |
|
stamparm
|
be5ce760b6
|
Fix for an Issue #485 (failing back to single-thread mode if over some bisection length)
|
2013-07-09 10:24:48 +02:00 |
|
stamparm
|
a7787e83b8
|
Minor fix for case-insensitive union duplicates
|
2013-06-18 12:52:36 +02:00 |
|
stamparm
|
6b280d8da4
|
Putting 2 decimal places for debug messages with performed queries (e.g. to handle a problem with 0 seconds roundup)
|
2013-05-28 14:40:45 +02:00 |
|
stamparm
|
b26ecfe087
|
Patch for an Issue #449
|
2013-05-17 15:14:51 +02:00 |
|
stamparm
|
7ba9e75c97
|
Minor update related to the last commit
|
2013-05-16 15:23:20 +02:00 |
|
stamparm
|
7ea8dd9428
|
MySQL is specific (types are automatically being converted without any warning/error)
|
2013-05-16 15:12:36 +02:00 |
|
stamparm
|
41f0e91662
|
Minor update (related to last commit)
|
2013-05-13 14:50:03 +02:00 |
|
stamparm
|
8b64709c17
|
Completing implementation for an Issue #189 (union)
|
2013-05-09 16:36:03 +02:00 |
|
stamparm
|
3873805dab
|
Partial implementation for an Issue #189 (error-based; still partial union left)
|
2013-05-09 16:23:57 +02:00 |
|
stamparm
|
9fe5a8832f
|
Update for an Issue #189 (code refactoring of ProgressBar so it could be ready for usage in non-inference cases out of box)
|
2013-05-09 15:52:18 +02:00 |
|
stamparm
|
03be419d5d
|
Fix for an Issue #447
|
2013-05-07 13:25:30 +02:00 |
|
Miroslav Stampar
|
73917fc9c8
|
Minor update (same, but safer)
|
2013-04-11 21:25:44 +02:00 |
|
stamparm
|
8c9da95343
|
Style and consistency update (url -> URL)
|
2013-04-09 11:48:42 +02:00 |
|
stamparm
|
558ef0aaff
|
Minor fix
|
2013-03-19 10:42:20 +01:00 |
|
Miroslav Stampar
|
e9b86350f1
|
Patch for an Issue #403
|
2013-03-05 18:32:31 +01:00 |
|
Bernardo Damele
|
0e7f771be6
|
minor adjustment
|
2013-02-15 16:28:09 +00:00 |
|
Bernardo Damele
|
35aa785870
|
bug fix to make --predict-output work also with time-based technique
|
2013-02-15 16:25:33 +00:00 |
|
Miroslav Stampar
|
014e4e0055
|
Minor represenation fix
|
2013-02-15 14:48:24 +01:00 |
|
Bernardo Damele
|
4b9d8ed673
|
reverted a previous commit as not all distributions create a link file /usr/bin/python2 to the Python interpreter
|
2013-02-14 11:32:17 +00:00 |
|
Bernardo Damele
|
a67ef4117f
|
make sure to use Python 2 interpreter when default system Python is version 3
|
2013-02-14 11:25:04 +00:00 |
|
Bernardo Damele
|
e03010f48b
|
got rid of unnecessary output for API - #297
|
2013-02-05 15:00:06 +00:00 |
|
Miroslav Stampar
|
01219219fc
|
Minor bug fix (for --first/--last through problematic DBMSes)
|
2013-02-05 15:03:55 +01:00 |
|
Miroslav Stampar
|
31daefc7c9
|
Minor fix (skipping one uneccesary request in single-threaded --first/--last mode)
|
2013-02-05 13:51:35 +01:00 |
|
Miroslav Stampar
|
4f2981f163
|
Minor fix
|
2013-02-04 16:37:54 +01:00 |
|
Miroslav Stampar
|
f4b8a3c1d8
|
Bug fix for boolean (multithreaded Ctrl+C) resumed values
|
2013-02-04 15:49:29 +01:00 |
|
Miroslav Stampar
|
235153ab39
|
Removal of unused imports
|
2013-02-04 15:29:13 +01:00 |
|
Bernardo Damele
|
9370f96a67
|
step by step getting there to partial output presentation to restful API (issue #297), not quite yet though..
|
2013-02-03 22:09:33 +00:00 |
|
Bernardo Damele
|
dc2bbbeaa7
|
minor revert
|
2013-02-03 20:55:58 +00:00 |
|
Bernardo Damele
|
f8bc74758c
|
improvement to restful API to store to IPC database partial entries, not yet functional (issue #297)
|
2013-02-03 11:31:05 +00:00 |
|
Miroslav Stampar
|
f41460f8d8
|
Better naming
|
2013-01-29 20:53:11 +01:00 |
|
Miroslav Stampar
|
c06f94e2c8
|
Fix for an Issue #378
|
2013-01-25 16:38:41 +01:00 |
|
Bernardo Damele
|
f848f259a6
|
upper() -D value for certain DBMSes
|
2013-01-23 16:22:28 +00:00 |
|
Bernardo Damele
|
012815333c
|
minor bug fix to ignore provided -D when brute-forcing columns/tables names and the DBMS is either Access, Firebird or SQLite
|
2013-01-23 15:52:03 +00:00 |
|
Miroslav Stampar
|
d6a361f859
|
Proper implementation for --technique=Q --dbms=Firebird
|
2013-01-22 16:31:26 +01:00 |
|
Miroslav Stampar
|
59b02539ca
|
More general approach regarding that last commit
|
2013-01-22 11:34:34 +01:00 |
|
Miroslav Stampar
|
75bf8528d1
|
Minor just in case update
|
2013-01-21 14:50:43 +01:00 |
|
Miroslav Stampar
|
069c6acabd
|
Another update for an Issue #362
|
2013-01-20 22:47:26 +01:00 |
|
Miroslav Stampar
|
b4a55a809e
|
Refactoring DBMS string escaping functions
|
2013-01-20 13:45:58 +01:00 |
|
Bernardo Damele
|
c95119559e
|
minor bug fix
|
2013-01-19 00:41:51 +00:00 |
|
Bernardo Damele
|
0e78fbef56
|
correctly format SQLi payload for inline query technique
|
2013-01-19 00:28:03 +00:00 |
|
Miroslav Stampar
|
601eb1e49a
|
Unescaping is renamed to escaping
|
2013-01-18 15:40:37 +01:00 |
|
Bernardo Damele
|
a43202f3c0
|
updated copyright
|
2013-01-18 14:07:51 +00:00 |
|