Miroslav Stampar
|
1d93a03eeb
|
introducing mnemonics
|
2011-06-15 11:58:50 +00:00 |
|
Miroslav Stampar
|
d55a242908
|
minor improvement. messages are now warnings (not errors because lots of them are not causing problems for a normal usage) and most of all it's being checked only if the --dependencies is used (until now this switch has been ignored and turned on by default - always)
|
2011-06-14 19:38:35 +00:00 |
|
Bernardo Damele
|
8978fded03
|
typo fix
|
2011-06-13 19:00:27 +00:00 |
|
Bernardo Damele
|
7152a1ed3b
|
Added --dependences to show which sqlmap dependences are not available
|
2011-06-13 18:44:02 +00:00 |
|
Miroslav Stampar
|
2da56ea507
|
fix of a language bug
|
2011-06-11 21:17:30 +00:00 |
|
Miroslav Stampar
|
9331abb96f
|
minor update
|
2011-06-11 08:33:36 +00:00 |
|
Miroslav Stampar
|
f8dde2c23b
|
adding --titles switch (killer switch for pages with lots of dynamicity and/or international ones)
|
2011-06-10 23:18:43 +00:00 |
|
Miroslav Stampar
|
fae089646b
|
minor fix
|
2011-06-09 08:38:17 +00:00 |
|
Miroslav Stampar
|
9202fedf7b
|
minor fix
|
2011-06-09 08:14:54 +00:00 |
|
Miroslav Stampar
|
af5fe457bd
|
revert of the revert (it's a good idea to have it like this because of problems with e.g. --text-only and binary content)
|
2011-06-09 07:53:31 +00:00 |
|
Miroslav Stampar
|
8ec4bc9d9d
|
revert of the last commit. have to think about it
|
2011-06-09 06:32:53 +00:00 |
|
Miroslav Stampar
|
9c093d91f2
|
minor update
|
2011-06-09 06:14:35 +00:00 |
|
Bernardo Damele
|
0d8d6a4ace
|
Cosmetics
|
2011-06-08 16:08:20 +00:00 |
|
Bernardo Damele
|
70cac24909
|
Cosmetics
|
2011-06-08 15:31:27 +00:00 |
|
Bernardo Damele
|
64bef644c3
|
This was missing
|
2011-06-08 15:30:59 +00:00 |
|
Bernardo Damele
|
0d3e8a76d8
|
Cosmetics and a missing param
|
2011-06-08 14:40:42 +00:00 |
|
Miroslav Stampar
|
4a9640160e
|
more concise
|
2011-06-08 14:35:23 +00:00 |
|
Miroslav Stampar
|
6b81eef65a
|
refactoring
|
2011-06-08 14:30:12 +00:00 |
|
Bernardo Damele
|
7da3d8dbd1
|
minor layout adjustment
|
2011-06-08 13:01:33 +00:00 |
|
Miroslav Stampar
|
f65abdaae3
|
added switch --cookie-del by request
|
2011-06-08 08:27:24 +00:00 |
|
Miroslav Stampar
|
4eeeb3655e
|
asking and skipping to the next google result page if no usable links found
|
2011-06-07 23:24:17 +00:00 |
|
Miroslav Stampar
|
26062ec71e
|
minor update
|
2011-06-07 15:13:51 +00:00 |
|
Miroslav Stampar
|
50dde39e68
|
minor update
|
2011-06-07 10:32:18 +00:00 |
|
Miroslav Stampar
|
7a3cc38e3c
|
refactoring and stabilization of multithreading
|
2011-06-07 09:50:00 +00:00 |
|
Miroslav Stampar
|
03c3f83893
|
minor fix
|
2011-06-06 13:34:49 +00:00 |
|
Miroslav Stampar
|
24ed99e5a3
|
fix for a bug reported by aboynes@gmail.com
|
2011-06-06 08:50:48 +00:00 |
|
Miroslav Stampar
|
f27181c628
|
minor improvement for blind based injections with reflected values
|
2011-06-03 14:41:36 +00:00 |
|
Miroslav Stampar
|
e9eafc2e94
|
minor update
|
2011-06-03 14:13:22 +00:00 |
|
Miroslav Stampar
|
64a862ed58
|
minor usability update
|
2011-06-03 14:04:02 +00:00 |
|
Miroslav Stampar
|
faf7814869
|
fix for a fuzz "bug" reported by daniele.rivetti@yahoo.com
|
2011-06-03 11:01:26 +00:00 |
|
Miroslav Stampar
|
08d6bb4f23
|
minor fix
|
2011-06-02 22:13:31 +00:00 |
|
Miroslav Stampar
|
8aa5625cd0
|
proper fix related to the last commit
|
2011-06-01 23:00:18 +00:00 |
|
Miroslav Stampar
|
63145236b9
|
minor fix
|
2011-05-31 21:53:29 +00:00 |
|
Miroslav Stampar
|
3c12799ff0
|
minor improvement
|
2011-05-30 20:34:34 +00:00 |
|
Miroslav Stampar
|
89559d1b0a
|
better regex and now after we have that automatic switch off for reflective removal mechanism it's not so important to change it
|
2011-05-30 20:18:30 +00:00 |
|
Miroslav Stampar
|
20988e58ed
|
warp 5 mr spock :)
|
2011-05-30 09:46:32 +00:00 |
|
Miroslav Stampar
|
001cbff2a9
|
speed up of 2 times for partial union technique
|
2011-05-30 09:07:48 +00:00 |
|
Miroslav Stampar
|
97820949f5
|
minor update
|
2011-05-30 08:33:01 +00:00 |
|
Miroslav Stampar
|
23d7820de7
|
minor update
|
2011-05-29 23:56:41 +00:00 |
|
Miroslav Stampar
|
86455ceb9c
|
implementation of multithreading for UNION and ERROR techniques
|
2011-05-29 23:17:50 +00:00 |
|
Miroslav Stampar
|
d51efa679d
|
typo update
|
2011-05-29 06:26:28 +00:00 |
|
Miroslav Stampar
|
f848cc779e
|
adding legal disclaimer as latest situation (these days news headlines) seems out of control
|
2011-05-28 18:54:14 +00:00 |
|
Miroslav Stampar
|
eb9b84d1da
|
type correction
|
2011-05-28 17:53:05 +00:00 |
|
Miroslav Stampar
|
03ef53f00a
|
update regarding mysql function resolution and versionedkeywords
|
2011-05-28 17:34:43 +00:00 |
|
Miroslav Stampar
|
c11ea35d53
|
adding some user input for "refreshing" cases (like redirect ones)
|
2011-05-27 22:42:23 +00:00 |
|
Miroslav Stampar
|
8227298057
|
user friendliness uber 9000
|
2011-05-27 08:30:52 +00:00 |
|
Miroslav Stampar
|
45caadbd4a
|
important update - finally found what was causing headache for UNION payloads in noticeable number of cases
|
2011-05-26 21:54:19 +00:00 |
|
Miroslav Stampar
|
4f46a5ab63
|
minor usability enhancement regarding warning for --text-only switch
|
2011-05-26 20:48:18 +00:00 |
|
Miroslav Stampar
|
ff030e4d24
|
minor cleanup of the leftover
|
2011-05-26 17:37:24 +00:00 |
|
Miroslav Stampar
|
bf2b58ba82
|
minor update
|
2011-05-26 15:23:28 +00:00 |
|
Miroslav Stampar
|
b6fe5b12a4
|
adding --schema to the wizard/Basic as it looks like a cool thingy to put there
|
2011-05-26 14:30:05 +00:00 |
|
Miroslav Stampar
|
f3ed61af5f
|
bug fix when using inference and kb.pageEncoding is None (like in binary cases)
|
2011-05-25 21:12:12 +00:00 |
|
Miroslav Stampar
|
0e480a9921
|
adding SYS to the ORACLE_SYSTEM_DBS
|
2011-05-25 10:55:47 +00:00 |
|
Miroslav Stampar
|
2f456bee75
|
minor beautification
|
2011-05-25 08:14:39 +00:00 |
|
Miroslav Stampar
|
8b7a3c5a6b
|
making it easier for totally dummy users
|
2011-05-24 17:24:01 +00:00 |
|
Miroslav Stampar
|
bec2c04671
|
helping dummy users
|
2011-05-24 17:15:25 +00:00 |
|
Miroslav Stampar
|
a3466ff79c
|
serving everything for the users
|
2011-05-24 16:34:08 +00:00 |
|
Miroslav Stampar
|
69eb173eca
|
minor just in case patch
|
2011-05-24 15:07:37 +00:00 |
|
Miroslav Stampar
|
f774d8fea0
|
proper Tor settings (reverted r3915 and implemented it the right way)
|
2011-05-24 11:06:58 +00:00 |
|
Miroslav Stampar
|
a536bf210f
|
improved redirection mechanism
|
2011-05-23 23:20:03 +00:00 |
|
Miroslav Stampar
|
128a012121
|
this was causing that --suffix trouble
|
2011-05-23 19:59:07 +00:00 |
|
Miroslav Stampar
|
bfe8e51b7c
|
minor fix for retrieving stuff like "SELECT * FROM testdb..users"
|
2011-05-23 19:45:40 +00:00 |
|
Miroslav Stampar
|
4542d4535f
|
minor beautification
|
2011-05-23 14:28:05 +00:00 |
|
Miroslav Stampar
|
0ed03d474f
|
now supporting "blank tables" - schema of the table will be preserved, even if it's empty - especially nice feature for --replicate
|
2011-05-23 11:09:44 +00:00 |
|
Miroslav Stampar
|
fb23beef6f
|
most elegant way i could think of to deal with "collation incompatibilities" issue on some MySQL/UNION cases (affected about 5% of all targets tested)
|
2011-05-22 19:14:36 +00:00 |
|
Miroslav Stampar
|
9b2623514a
|
one bug fix for Host header (value should be without port number); one improvement for --tables - when no tables ask user if he wants to brute force them; one tweak - adding kb.ignoreTimeout for --tables
|
2011-05-22 09:48:46 +00:00 |
|
Miroslav Stampar
|
2ea613b170
|
type correction and adding global flag kb.ignoreTimeout which could be useful
|
2011-05-22 08:24:13 +00:00 |
|
Miroslav Stampar
|
a58aaf2e1a
|
better format for results file (easier for sorting when lots of files)
|
2011-05-22 07:02:36 +00:00 |
|
Miroslav Stampar
|
25fff8c135
|
changes in handling --tor (using SOCKS instead of HTTP for handling Tor - more standard way; doesn't require proxy bundle; fixes problems with default proxy ports on Win/Linux)
|
2011-05-21 11:46:57 +00:00 |
|
Miroslav Stampar
|
9e5856caf8
|
improvement for recognition of scalar vs multiple-row commands
|
2011-05-19 16:45:05 +00:00 |
|
Miroslav Stampar
|
db72428765
|
minor update
|
2011-05-19 15:57:29 +00:00 |
|
Miroslav Stampar
|
f40c6b2ce7
|
added --cookie for maskSensitiveData too
|
2011-05-19 15:42:59 +00:00 |
|
Miroslav Stampar
|
9832fc42d4
|
minor improvement for --tamper (now standard tamper scripts can be used like --tamper=randomcase)
|
2011-05-18 21:47:40 +00:00 |
|
Miroslav Stampar
|
3048e9f710
|
minor refactoring
|
2011-05-17 23:03:31 +00:00 |
|
Miroslav Stampar
|
cc07e5dc97
|
added --charset option to force charset encoding of the retrieved data (e.g. when the backend collation is different than the current web page charset) as requested by devon.mitchell1988@yahoo.com
|
2011-05-17 22:55:22 +00:00 |
|
Miroslav Stampar
|
dfe81cc66f
|
minor yielding
|
2011-05-16 20:14:10 +00:00 |
|
Miroslav Stampar
|
a5ad4621c9
|
minor refactoring
|
2011-05-16 20:09:12 +00:00 |
|
Miroslav Stampar
|
faa74cd2bc
|
introducing results file for multiple target mode
|
2011-05-15 22:21:38 +00:00 |
|
Miroslav Stampar
|
90e84c9a6d
|
removing xmlcharrefreplace error handler as it seems that it wasn't such a good idea at the end
|
2011-05-15 21:43:38 +00:00 |
|
Miroslav Stampar
|
c3bb5a03e1
|
minor improvement
|
2011-05-14 20:09:37 +00:00 |
|
Miroslav Stampar
|
3484a4426b
|
fix for a bug reported by itxx@qq.com (TypeError: encode() takes no keyword arguments)
|
2011-05-14 19:57:28 +00:00 |
|
Miroslav Stampar
|
a7d7be5ce0
|
bug fix ('Host' header was being set to the conf.hostname for all getPages causing problems in some cases when retrieved page was not coming from that same Host)
|
2011-05-13 01:01:53 +00:00 |
|
Miroslav Stampar
|
70688fb8b5
|
minor enhancement for dumping 'None' values (proper way should be empty string because None is too pythonic)
|
2011-05-12 12:00:17 +00:00 |
|
Miroslav Stampar
|
0b2da2f9f5
|
minor beautification for --tor switch
|
2011-05-12 05:46:17 +00:00 |
|
Miroslav Stampar
|
e05a9c0554
|
i was probably very tired or very stupid to do this
|
2011-05-11 13:13:46 +00:00 |
|
Miroslav Stampar
|
2ab9e30f7a
|
bug fix
|
2011-05-11 12:54:33 +00:00 |
|
Miroslav Stampar
|
53065ee1fb
|
adding ordered set for kb.targetUrls (now the order of appereance in multiple targets mode will be respected)
|
2011-05-11 08:55:48 +00:00 |
|
Miroslav Stampar
|
5ee07b90b9
|
added -m switch for bulk loading multiple targets
|
2011-05-11 08:46:40 +00:00 |
|
Miroslav Stampar
|
120b0d756e
|
unfix
|
2011-05-10 21:33:06 +00:00 |
|
Miroslav Stampar
|
192c685bc8
|
changing conf attribute to a more proper name
|
2011-05-10 20:48:34 +00:00 |
|
Miroslav Stampar
|
deae534ee7
|
minor refactoring
|
2011-05-10 20:44:36 +00:00 |
|
Bernardo Damele
|
97bc816aeb
|
layout
|
2011-05-10 16:24:09 +00:00 |
|
Bernardo Damele
|
3a8309c4b0
|
Major bug fix to detect UNION query technique and various improvements to parsing and using of --union-char and --union-cols switches
|
2011-05-10 15:34:54 +00:00 |
|
Miroslav Stampar
|
707edc7b1a
|
fix for a bug (previously --dbms="mysql 4" was ignored and abruptly terminated while the mechanism was here all along)
|
2011-05-10 13:28:07 +00:00 |
|
Miroslav Stampar
|
a64407d9db
|
minor bug fix for multithreading and lots of connection retries
|
2011-05-10 12:40:01 +00:00 |
|
Miroslav Stampar
|
22a1870c2c
|
adding some constraining to number of used threads on brute force switches together with a warning in case of connection exception(s) with --threads>1
|
2011-05-10 12:32:07 +00:00 |
|
Miroslav Stampar
|
ec4d9178f8
|
minor update related to the previous commit
|
2011-05-08 06:28:58 +00:00 |
|
Miroslav Stampar
|
4d6e7c738c
|
minor update
|
2011-05-08 06:17:43 +00:00 |
|
Bernardo Damele
|
6653907700
|
forgot in last commit
|
2011-05-07 21:13:56 +00:00 |
|
Bernardo Damele
|
1151af52bb
|
More fix for save/resume of --technique
|
2011-05-07 21:08:14 +00:00 |
|