| 
							
							
								 Miroslav Stampar | 858cb25975 | update | 2010-02-24 23:40:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2a07af2294 | removed pdb tracing | 2010-02-20 22:36:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0debc95ad4 | some fixes | 2010-02-20 22:31:54 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | d1e3596382 | Minor UPX adjustment | 2010-02-20 19:02:55 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0ed5ba5559 | minor update | 2010-02-16 13:24:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c4951fd631 | some updates regarding --os-shell option | 2010-02-16 13:20:34 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | dc06b40ddc | Minor exception message fix | 2010-02-11 23:07:33 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 89dc99188d | --read-file on PostgreSQL now relies on the new sys_fileread() UDF so that also binary files can be read. Fixed a minor bug in custom UDF injection feature --udf-inject.
Major code refactoring. | 2010-02-11 22:57:50 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 00a23ace9a | some changes regarding web takeover | 2010-02-09 14:27:41 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 5c92fad5dc | Avoid to check for existence of not needed UDFs and minor code adjustment for cleanup() method | 2010-02-05 23:14:16 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d291464cd4 | code refactoring regarding path normalization | 2010-02-04 14:50:54 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | dbd52c52e4 | minor fix | 2010-02-04 14:39:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ec63fc4036 | code refactoring - added functions posixToNtSlashes and ntToPosixSlashes | 2010-02-04 14:37:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 87239476af | more fixes :) | 2010-02-04 10:10:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e4699f389d | some bug fixes regarding --os-shell usage against windows servers | 2010-02-04 09:49:31 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ea045eaa2f | fixed serious issue with adding file paths into kb.absFilePaths (dirname was wrongly added, and afterwards getDirs used dirname of dirname) also, fixed some issues with Windows paths | 2010-02-03 16:40:12 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7c88e32f9d | bug fix for 404 program termination during shell upload attempt | 2010-02-03 16:16:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 565433097e | used normalizePath instead of os.path.normalize | 2010-02-03 16:10:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 87c8bdbc29 | removed pdb tracing | 2010-02-03 14:52:29 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c74b920f54 | bug fix | 2010-02-03 14:49:28 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 979c919dc7 | Minor logging message adjustment | 2010-01-29 22:58:12 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | e8b0fd90c8 | Minor bug fix | 2010-01-29 19:32:02 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 767c67e37a | --priv-esc now relieas on more powerful and complete getsystem Meterpreter command that also implements kitrap0d as 4th technique | 2010-01-29 14:57:33 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 061794650f | minor fix | 2010-01-29 10:15:05 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 92817159dc | cloaked upx for windows (used mkstemp because of execution and file access rights problem) | 2010-01-29 10:12:09 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 200518724c | By default do not use Churrasco, but still let the user choose it. The default technique to privilege escalate the OS user to SYSTEM when --priv-esc is provided now it 'run kitrap0d'. | 2010-01-29 02:27:50 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 7b8316728c | Major bug fix in takeover functionalities on Microsoft SQL Server | 2010-01-29 00:09:05 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 6f5d2ed171 | Minor cosmetic adjustments | 2010-01-28 17:07:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a2077bfc0e | quick fix | 2010-01-28 16:56:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 732ed48e2b | some refactoring regarding decloaking | 2010-01-28 16:50:34 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | dcbbad642d | Minor self fix, switched to rc6 | 2010-01-28 10:27:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f6b447f6e7 | fix for "NameError: global name 'webFileStreamUpload' is not defined" | 2010-01-28 08:54:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 921e449454 | added support for cloaking Churrasco.exe file | 2010-01-28 00:07:33 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 4559ded6c1 | added new line at the end of the file | 2010-01-27 17:02:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f4b8ce5c72 | fix for 'No such file or directory' OSError exception | 2010-01-27 17:00:54 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d0acb1c5a3 | another fix. hope it works :) | 2010-01-27 16:01:50 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f8056f4098 | quick fix regarding usage of StringIO instead of file stream | 2010-01-27 15:44:35 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1d15c595a4 | minor fix | 2010-01-27 14:08:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e63428207c | modified a way to handle shell scripts | 2010-01-27 13:59:25 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 6437c16156 | run kitrap0d script along with listing Windows Impersonation Tokens via meterpreter's incognito extension when --priv-esc is provided (see #149). | 2010-01-26 01:14:44 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | f337cd6e0a | Minor speedup to check if sqlmap's UDF have already been created | 2010-01-16 21:46:35 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | c4215ce8d2 | Minor code refactoring | 2010-01-14 20:42:45 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 1d968f51e9 | More code refactoring | 2010-01-14 15:11:32 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | c9863bc1d2 | Minor code refactoring | 2010-01-14 14:33:08 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 070ccc30e9 | Added automatic support in --os-pwn to use the web uploader/backdoor to upload and execute the Metasploit payload stager when stacked queries SQL injection is not supported, for instance on MySQL/PHP and MySQL/ASP. Updated ChangeLog.
Major code refactoring. | 2010-01-14 14:03:16 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | bb61010a45 | Avoid useless checks for --os-bof (no need to check for DBA or for xp_cmdshell). Minor code restyling. | 2010-01-04 15:02:56 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | ce022a3b6e | sqlmap 0.8-rc3: Merge from Miroslav Stampar's branch fixing a bug when verbosity > 2, another major bug with urlencoding/urldecoding of POST data and Cookies, adding --drop-set-cookie option, implementing support to automatically decode gzip and deflate HTTP responses, support for Google dork page result (--gpage) and a minor code cleanup. | 2010-01-02 02:02:12 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | e4e081cdc6 | sqlmap 0.8-rc2: minor enhancement based on msfencode 3.3.3-dev -t exe-small so that also PostgreSQL supports again the out-of-band via Metasploit payload stager optionally to shellcode execution in-memory via sys_bineval() UDF. Speed up OOB connect back. Cleanup target file system after --os-pwn too. Minor bug fix to correctly forge file system paths with os.path.join() all around. Minor code refactoring and user's manual update. | 2009-12-17 22:04:01 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | e28b98a366 | Minor layout adjustments | 2009-12-02 22:52:17 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 4779a5fe0f | Minor layout adjustment | 2009-11-16 16:39:31 +00:00 |  |