| 
							
							
								 Miroslav Stampar | 775e0df04b | Update for an Issue #278 | 2012-12-05 10:45:17 +01:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7c16bfe025 | Fix for error-based MsSQL dumping (in some cases failed because of wrong order - e.g. MIN(SUBSTRING( instead of SUBSTRING(MIN ) | 2012-11-29 10:51:59 +01:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a40d7a5bca | Minor improvement (safer to use column name in COUNT than *, especially when only one column is needed) | 2012-11-15 15:06:54 +01:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 01f481c332 | Minor refactoring of dictionaries | 2012-08-21 11:19:15 +02:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 93d35fe522 | Minor update regarding Issue #129 | 2012-07-30 21:43:32 +02:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 162da75a04 | modified homepage address | 2012-07-12 18:38:03 +01:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | ea9c66108e | cleanup for issue #68 | 2012-07-12 15:38:43 +01:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cba2a26b68 | Finishing Issue #75 (inference dumping) | 2012-07-12 14:46:57 +02:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 65639cdda6 | First update for Issue #75 (error-based dumping) | 2012-07-12 14:31:28 +02:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 373fea03a3 | fixed display of TABs | 2012-07-06 15:13:23 +01:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 438a636973 | Fix for issue Issue #60 | 2012-07-06 15:36:32 +02:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 76f7f907c6 | Minor update for Issue #61 | 2012-07-06 14:33:40 +02:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6a05e3fd79 | Fix for Issue #61 | 2012-07-06 14:24:44 +02:00 |  | 
			
				
					| 
							
							
								 jekil | c39e5a85ba | Removed $id$ tags | 2012-06-27 20:56:43 +02:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6c4bd84d18 | minor fix (turning back the functionality of kb.suppressResumeInfo) | 2012-06-25 16:19:51 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 302d782a0f | minor style update | 2012-06-19 08:33:51 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | facce2c0df | some more cleanup | 2012-06-14 13:50:36 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3a90105fbb | minor refactoring | 2012-06-14 13:38:53 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 56a3431be6 | minor update for empty tables (skipping other techniques) | 2012-05-09 10:34:21 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ac5a752b12 | Oracle's XMLType doesn't like '#' char too | 2012-03-01 11:59:37 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c36cbbb3ae | minor fix | 2012-02-24 14:54:10 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f94b91ad87 | added helper function for HashDB data storing/retrieval | 2012-02-24 13:07:20 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 086c3a3662 | minor fix | 2012-02-23 13:31:50 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b3bd4144f5 | removing of unused imports together with some general code refactoring | 2012-02-22 10:40:11 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | bcf3255fe1 | implementation of switch --hex for 4 major DBMSes | 2012-02-21 11:44:48 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | aee269cc14 | gazillion changes, nothing will work, muhahaha | 2012-02-17 14:22:48 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e1f86c97c4 | minor refactoring | 2012-02-16 09:46:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2b05ded9c3 | just a makeup | 2012-02-07 12:05:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8c45ff0d57 | bug fix | 2012-02-03 10:38:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 95f89ab63a | updating copyright date | 2012-01-11 14:59:46 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 18930539cd | more concise language | 2012-01-07 17:45:45 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 29f502fe29 | some refactoring | 2011-12-28 16:27:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 22c3fe49bb | some refactoring | 2011-12-28 13:50:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | abb401879c | minor update | 2011-12-22 20:42:57 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8585107e3d | minor update | 2011-12-22 12:21:30 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f622995a29 | compatibility with partial union and error technique resumed data | 2011-12-22 12:20:21 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9f68e54fff | minor cleanup | 2011-12-22 10:59:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 81bd9a201b | minor refactoring | 2011-12-21 11:50:49 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 23bf52e496 | minor refactoring | 2011-10-24 09:55:50 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e3a719e7d2 | minor update | 2011-10-11 22:40:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7956390631 | minor update | 2011-10-11 22:27:49 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a7a29f33ad | minor update | 2011-10-11 21:58:57 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7e80274fac | refactoring | 2011-09-25 21:10:45 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 744636a8c1 | switching to SQLite resume support (on error and union techniques this moment) | 2011-09-25 20:36:32 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cb0981d858 | proper way of handling 0 length results (as in __goInferenceProxy) | 2011-08-02 08:39:32 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 938716e361 | Proper fix for --start and --stop consistency amongst different techniques | 2011-07-26 10:06:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6bbb8139a0 | update (smaller memory footprint in postprocessing phase because of safecharencode part) | 2011-07-25 20:40:31 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5770c08784 | minor optimization and refactoring | 2011-07-25 20:17:44 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ec1bc0219c | hello big tables, this is sqlmap, sqlmap this is big tables | 2011-07-24 09:19:33 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a89140e1ce | revisit of Oracle error-based payloads (added replace for '@' as a problematic char for XMLType function) | 2011-07-23 06:07:00 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | aedcf8c8d7 | Changed homepage address | 2011-07-07 20:10:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 34d9a91af1 | bulk of fixes | 2011-07-02 22:48:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9e232256f4 | reverting that last commit because there is a  mess with default dumping (startLimit is set to 0 which is not so friendly with --start and --stop logic) | 2011-06-21 18:29:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3536320fc9 | --stop is inclusive ("Last query output entry to retrieve") | 2011-06-21 18:08:33 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | cd07139919 | Layout adjustments | 2011-06-18 11:58:14 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e7e23d1b79 | fix for a Ctrl+C bug reported by nightman@email.de | 2011-06-07 17:16:01 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7a3cc38e3c | refactoring and stabilization of multithreading | 2011-06-07 09:50:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | fc96764f80 | minor bug fix ("trimmed" error message was shown for empty cases too because u'' or None == None) | 2011-06-01 22:06:06 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 091c174bc4 | better language | 2011-06-01 08:30:06 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b79dae6e95 | minor update | 2011-05-30 14:49:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d5ede6afb4 | fix for a dirty reading issue reported by skysbsb@gmail.com (IndexError: list index out of range) | 2011-05-30 06:38:44 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6fd8602f01 | minor update | 2011-05-29 23:33:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 86455ceb9c | implementation of multithreading for UNION and ERROR techniques | 2011-05-29 23:17:50 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9e5856caf8 | improvement for recognition of scalar vs multiple-row commands | 2011-05-19 16:45:05 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c64eb38a8b | same thing as for the last commit, but for error technique this time | 2011-05-12 11:52:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 83fac3f6d9 | fix for proper MSSQL error chunking in some cases (not screwing output length toward lower values at chunk phase) | 2011-05-03 21:12:51 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e6f010734e | minor fix for cases when the retrieved output is safe encoded (like for --os-shell) | 2011-05-03 16:14:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 742b0ef76e | major improvement of ERROR data retrieval on MSSQL | 2011-05-03 13:25:20 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 9a4ae7d9e2 | More code refactoring of Backend class methods used | 2011-04-30 14:54:29 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | f56d135438 | Minor code restyling | 2011-04-30 13:20:05 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f88aa4b165 | implemented suppressResumeInfo mechanism (huge slowdown on large tables) | 2011-04-22 19:58:10 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 8d8fc2bbd8 | cosmetics | 2011-04-21 10:17:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e4d3190f41 | reverting back to NVARCHAR because of error technique | 2011-04-20 12:59:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3607f03a9e | fix of a minor typo | 2011-04-20 12:42:35 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1286cc0913 | now showing trimmed output in for of warning message (UNION and ERROR techniques affected) | 2011-04-20 12:41:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3b6f9945ae | minor fix regarding report from nightman@email.de (...from time to time sqlmap lost the connection...) | 2011-04-15 14:15:29 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0387654166 | update of copyright string (until year) | 2011-04-15 12:33:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | bb99bd2fbe | one more commit related to the issue with displaying of garbled characters | 2011-04-14 09:43:36 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 04986be4b9 | update regarding safe character output together with a small fix for newlines | 2011-04-14 09:31:45 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c193b896be | just in case update to prevent gibberish "retrieved: " outputs | 2011-04-12 23:07:50 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6fa2fd139c | implemented support for __pivotDumpTable on MSSQL as normal tables tend to not play well with normal TOP 1 ..NOT IN..ORDER BY mechanism if the argument for ORDER BY is not the unique one (returns only number of rows equal to the number of distinct values for that field) | 2011-04-08 15:17:57 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 228cc68747 | fix for those ugly DEBUG messages in brute mode | 2011-04-08 11:02:21 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 8b14a9eaa7 | Minor code adjustments | 2011-04-06 14:40:45 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 3948cd9e77 | Minor layout adjustments | 2011-03-31 14:13:53 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0f7bce5c66 | fixing a huge mess going on because of counting on error and union techniques | 2011-03-23 11:36:40 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7613134515 | it was a real pain in the ass to have SELECT COUNT(*) for all rows (it was processed by a limit logic) | 2011-03-22 12:37:05 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9479a68eb5 | minor fix regarding last commit | 2011-03-22 12:21:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c24ed6e622 | minor fix related to a bug reported by warninggp@gmail.com | 2011-03-22 09:22:48 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b5c9ccb755 | Oracle XML based error payload has problems with char $ as with space | 2011-03-21 13:13:12 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9b1f2d82d0 | minor update (that .strip() was a leftover) | 2011-03-20 23:20:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | db992a0a86 | mssql likes to htmlescape error reports | 2011-03-20 23:16:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | beba69faa9 | implementation of request from Santiago (look for error based responses in redirects) | 2011-03-17 09:12:28 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | d8a76ebe34 | Minor bug fix for counting of entries for error-based and partial UNION query SQL injection techs | 2011-03-11 16:03:19 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 3cb0ca4b63 | Minor bug fix for --privileges on PgSQL with error-based SQL inj technique | 2011-03-11 15:24:25 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 83d7803ce7 | other techniques use dataToStdout for retrieved string, hence this update (also, fixing ugly retrieved: 0 or 1 while doing fingerprinting --flush-session -f --technique=2) | 2011-02-12 20:03:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3de6117253 | revert of the r3247 (output always has to be appended to the outputs - no matter of it's value) | 2011-02-09 09:53:59 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 98ca1702ae | los cosmeticado | 2011-02-08 16:30:32 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 87e36796c6 | just to not cause confusion | 2011-02-08 16:29:42 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | dcb9c93328 | minor cleanup | 2011-02-08 16:27:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 37f7001143 | first commit with mysql/error/substringing | 2011-02-08 16:23:33 +00:00 |  |