Miroslav Stampar
|
bf2b58ba82
|
minor update
|
2011-05-26 15:23:28 +00:00 |
|
Miroslav Stampar
|
79f0b3a92a
|
adding support for --start and --stop for __pivotDumpTable
|
2011-05-26 15:16:57 +00:00 |
|
Miroslav Stampar
|
b6fe5b12a4
|
adding --schema to the wizard/Basic as it looks like a cool thingy to put there
|
2011-05-26 14:30:05 +00:00 |
|
Miroslav Stampar
|
a397baa89a
|
fix for a bug reported by viniciusmaxdaloop@gmail.com and few related patches
|
2011-05-26 08:17:21 +00:00 |
|
Miroslav Stampar
|
1067d43f14
|
minor update
|
2011-05-23 19:16:29 +00:00 |
|
Miroslav Stampar
|
0ed03d474f
|
now supporting "blank tables" - schema of the table will be preserved, even if it's empty - especially nice feature for --replicate
|
2011-05-23 11:09:44 +00:00 |
|
Miroslav Stampar
|
7b52bbe3fb
|
reverting that ignoreTimeout for --tables (because of this and that)
|
2011-05-22 09:59:19 +00:00 |
|
Miroslav Stampar
|
9b2623514a
|
one bug fix for Host header (value should be without port number); one improvement for --tables - when no tables ask user if he wants to brute force them; one tweak - adding kb.ignoreTimeout for --tables
|
2011-05-22 09:48:46 +00:00 |
|
Miroslav Stampar
|
2ea613b170
|
type correction and adding global flag kb.ignoreTimeout which could be useful
|
2011-05-22 08:24:13 +00:00 |
|
Miroslav Stampar
|
5a979f7667
|
minor bug fix for empty colList; also added "do you want to use LIKE" (LIKE is default) question when -C used
|
2011-05-19 17:35:33 +00:00 |
|
Miroslav Stampar
|
4efc284b83
|
adding more info for --passwords
|
2011-05-11 12:35:32 +00:00 |
|
Bernardo Damele
|
b5f090cc4f
|
Minor bug fix
|
2011-05-10 15:48:48 +00:00 |
|
Bernardo Damele
|
ac74557614
|
Minor adjustment for --dump-all
|
2011-05-08 10:25:40 +00:00 |
|
Bernardo Damele
|
356037ca22
|
cosmetics
|
2011-05-08 02:11:34 +00:00 |
|
Bernardo Damele
|
9955483052
|
Major improvement for --dump.
Minor improvement for --dump-all.
Minor bug fix for infinite loop
|
2011-05-08 02:08:18 +00:00 |
|
Bernardo Damele
|
d3589493d1
|
Temporary fix for bug reported by ultramegaman (infinite loop)
|
2011-05-07 23:28:59 +00:00 |
|
Bernardo Damele
|
aae140080e
|
SVN roll back, DB2 patch will be recommitted after testing:
$ svn merge https://svn.sqlmap.org/sqlmap/trunk/sqlmap@HEAD https://svn.sqlmap.org/sqlmap/trunk/sqlmap@3847 .
|
2011-05-06 10:27:43 +00:00 |
|
Miroslav Stampar
|
6e392b6054
|
applying contributed patch for DB2
|
2011-05-06 09:30:39 +00:00 |
|
Miroslav Stampar
|
8e8886cd20
|
minor improvement for --sql-shell/--sql-query (when non-SELECT default is N for retrieve data output which automatically does STACKED injection)
|
2011-05-01 21:41:14 +00:00 |
|
Bernardo Damele
|
64bb480414
|
Do not raise otherwise it won't work with --schema
|
2011-04-30 23:20:16 +00:00 |
|
Bernardo Damele
|
b31b861d7b
|
Major rewrote of --columns: now it accepts -D only (enumerate all tables' columns of a specific database), -D and -T (enumerate all columns of a specific database's table), -T (enumerate all columns of a current database's table), etc.
|
2011-04-30 22:10:27 +00:00 |
|
Bernardo Damele
|
cb9b9c4204
|
Code refactoring and improvements to --dbs and --tables: now --tables accepts also -D CD as an alias for Current Database and as usual multiple database comma-separated are supported too
|
2011-04-30 15:29:19 +00:00 |
|
Bernardo Damele
|
9a4ae7d9e2
|
More code refactoring of Backend class methods used
|
2011-04-30 14:54:29 +00:00 |
|
Bernardo Damele
|
36a9ddaacc
|
Minor bug fixes and code restyling for --privileges and --passwords
|
2011-04-30 14:50:27 +00:00 |
|
Bernardo Damele
|
f56d135438
|
Minor code restyling
|
2011-04-30 13:20:05 +00:00 |
|
Bernardo Damele
|
1a052245a6
|
duplicate code
|
2011-04-30 00:25:15 +00:00 |
|
Bernardo Damele
|
a5968fff3e
|
Added --count switch to count the number of entries for a specific table (when -T is provided), all database's tables (when only -D is provided) or all databases' tables when neither -D nor -T are provided
|
2011-04-30 00:22:22 +00:00 |
|
Bernardo Damele
|
529595fd85
|
Moved method below
|
2011-04-29 22:37:43 +00:00 |
|
Bernardo Damele
|
14bf6abb7e
|
Minor layout adjustment
|
2011-04-29 21:40:48 +00:00 |
|
Bernardo Damele
|
f449688f93
|
Proper resume of --schema data when calling with --columns switch, minor fixes too
|
2011-04-29 21:17:59 +00:00 |
|
Miroslav Stampar
|
a6015b59df
|
fix for a bug reported by jaccovantuijl@gmail.com (entries = zip(*[entries[colName] for colName in colList]))
|
2011-04-29 14:33:47 +00:00 |
|
Bernardo Damele
|
edac0b2558
|
Added switch --schema to enumerate DBMS schema and now --columns does not require a mandatory table (-T) anymore, instead it will act as an alias for --schema
|
2011-04-28 23:59:00 +00:00 |
|
Miroslav Stampar
|
88c76147e1
|
removed few trailing whitespace lines
|
2011-04-15 20:52:08 +00:00 |
|
Miroslav Stampar
|
c16b74ce1a
|
covering __pivotDumpTable for keyboard and connection exceptions too
|
2011-04-15 14:21:13 +00:00 |
|
Miroslav Stampar
|
0387654166
|
update of copyright string (until year)
|
2011-04-15 12:33:18 +00:00 |
|
Miroslav Stampar
|
aed994192e
|
disabling safecharencode for --banner
|
2011-04-15 08:15:21 +00:00 |
|
Miroslav Stampar
|
8ddac7fe5a
|
minor fix and speedup when pivoting empty table
|
2011-04-14 21:11:20 +00:00 |
|
Miroslav Stampar
|
384ca98ded
|
don't let sqlmapNoneDataException for one table to break whole dumpAll()
|
2011-04-14 20:56:12 +00:00 |
|
Miroslav Stampar
|
dbbaefa79d
|
minor update (pivot value should be safechardecoded)
|
2011-04-14 20:38:03 +00:00 |
|
Miroslav Stampar
|
d06ae9cd47
|
implemented retrieved items info for partial union too
|
2011-04-13 14:33:15 +00:00 |
|
Bernardo Damele
|
f4745a95ea
|
Possible fix for bug reported by David
|
2011-04-11 21:45:25 +00:00 |
|
Miroslav Stampar
|
941daa1645
|
just in case to prevent "object of type 'NoneType' has no len()" error reports
|
2011-04-11 11:59:02 +00:00 |
|
Miroslav Stampar
|
e20848c711
|
first commit toward v1.0 (it's smarter to start testing for pivot point from shorter column names as they tend to be some kind of identifiers)
|
2011-04-11 09:40:52 +00:00 |
|
Miroslav Stampar
|
c714ac6421
|
added support for handling binary data values (no more garbish chars)
|
2011-04-09 23:13:16 +00:00 |
|
Miroslav Stampar
|
6fa2fd139c
|
implemented support for __pivotDumpTable on MSSQL as normal tables tend to not play well with normal TOP 1 ..NOT IN..ORDER BY mechanism if the argument for ORDER BY is not the unique one (returns only number of rows equal to the number of distinct values for that field)
|
2011-04-08 15:17:57 +00:00 |
|
Miroslav Stampar
|
e8259a7665
|
minor update (now --dump also supports only -D parameter)
|
2011-04-07 22:38:13 +00:00 |
|
Bernardo Damele
|
bac53eeef1
|
Allow --dump-all to accept -D switch in order to dump all tables' entries for only one (or more, comma-separated) specified database(s)
|
2011-04-07 22:08:10 +00:00 |
|
Miroslav Stampar
|
60102209f6
|
quick fix for a bug reported by Kirill (AttributeError: 'NoneType' object has no attribute 'split')
|
2011-04-01 11:14:24 +00:00 |
|
Miroslav Stampar
|
b6af80bab3
|
refactoring, cleanup and improvement
|
2011-03-29 21:54:15 +00:00 |
|
Miroslav Stampar
|
4312a42b5d
|
another minor fix
|
2011-03-28 12:04:39 +00:00 |
|
Miroslav Stampar
|
3173adbf6b
|
minor update
|
2011-03-28 12:02:31 +00:00 |
|
Miroslav Stampar
|
73e5d20ade
|
bulk commit for safe/unsafe identificator naming (done and tested for all 4 major DBMSes) and one bug fix for --search-column on MSSQL (inside queries)
|
2011-03-28 11:01:55 +00:00 |
|
Miroslav Stampar
|
76b7e3517d
|
minor update
|
2011-03-27 07:58:15 +00:00 |
|
Miroslav Stampar
|
04c4578df7
|
minor fix
|
2011-03-26 05:55:49 +00:00 |
|
Miroslav Stampar
|
58f8703ecd
|
minor update before bedtime
|
2011-03-25 22:59:18 +00:00 |
|
Miroslav Stampar
|
ae12dee990
|
minor update
|
2011-03-25 22:08:54 +00:00 |
|
Miroslav Stampar
|
c9baa0094b
|
going global for protection of non-standard identificator naming
|
2011-03-25 22:02:28 +00:00 |
|
Miroslav Stampar
|
5a1f733a43
|
minor update (_ is part of normal identificator naming)
|
2011-03-25 21:49:20 +00:00 |
|
Miroslav Stampar
|
1a98095a93
|
minor improvement for that MySQL identification naming
|
2011-03-25 21:46:49 +00:00 |
|
Miroslav Stampar
|
48c4460e2c
|
bug fixed (there was a huge problem with space containing identifiers - fixed and tested for MySQL)
|
2011-03-25 21:22:06 +00:00 |
|
Miroslav Stampar
|
af39a441fa
|
minor improvement when --dbs returns no database names (like in many cases with MySQL 4)
|
2011-03-25 19:50:06 +00:00 |
|
Miroslav Stampar
|
f3858a5fcf
|
another fix related to the bug reported by Alone Shell
|
2011-03-24 17:08:14 +00:00 |
|
Miroslav Stampar
|
02379c01a2
|
minor update (will do "schema update" for sybase some other time; that COUNT(*) blew my mind)
|
2011-03-23 11:42:36 +00:00 |
|
Miroslav Stampar
|
0f7bce5c66
|
fixing a huge mess going on because of counting on error and union techniques
|
2011-03-23 11:36:40 +00:00 |
|
Miroslav Stampar
|
7ea45e9032
|
minor update for Sybase regarding last commit
|
2011-03-23 11:04:15 +00:00 |
|
Miroslav Stampar
|
b72cdfe9e6
|
fix for mssql regarding usage of schema names reported by jabra@spl0it.org
|
2011-03-23 10:40:34 +00:00 |
|
Miroslav Stampar
|
5291fe35c9
|
proper implementation of --dbs on Oracle (we are using now schema names as a counterpart to dbs in other DBMSes)
|
2011-03-21 11:29:43 +00:00 |
|
Bernardo Damele
|
74ef1e53c7
|
Minor bug fixes to --privileges for PostgreSQL query (corner case)
|
2011-03-11 14:54:41 +00:00 |
|
Miroslav Stampar
|
eb1cda7065
|
minor refactoring (more consistent)
|
2011-03-09 12:06:32 +00:00 |
|
Miroslav Stampar
|
62e3510387
|
minor refactoring
|
2011-03-09 11:37:37 +00:00 |
|
Miroslav Stampar
|
16b286982d
|
fix for a bug reported by nightman (AttributeError: 'list' object has no attribute 'split')
|
2011-03-07 09:50:43 +00:00 |
|
Bernardo Damele
|
60605b6e7c
|
Major bug fix to make --first and --last apply only to --dump's entries dump phase (in either of the blind SQL injection techs only)
|
2011-02-27 12:14:13 +00:00 |
|
Miroslav Stampar
|
13f0d5ce00
|
minor bug fix
|
2011-02-22 14:51:42 +00:00 |
|
Miroslav Stampar
|
640ba5d744
|
minor refactoring
|
2011-02-22 14:19:39 +00:00 |
|
Bernardo Damele
|
3e8c204121
|
Major bug fix to properly prepare UNION technique statement for --os-pwn and --is-dba
|
2011-02-21 16:00:56 +00:00 |
|
Miroslav Stampar
|
aac817935a
|
further improvement of MaxDB support
|
2011-02-20 22:41:42 +00:00 |
|
Miroslav Stampar
|
a3ba8b6928
|
--dump now works on MaxDB too
|
2011-02-20 22:07:12 +00:00 |
|
Miroslav Stampar
|
59e666d16e
|
--is-dba (related) update for Sybase
|
2011-02-20 17:28:06 +00:00 |
|
Miroslav Stampar
|
4d52f7fc6e
|
minor fix regarding --dump-table on Sybase for --technique=23
|
2011-02-20 16:58:01 +00:00 |
|
Miroslav Stampar
|
cc47737c44
|
minor update
|
2011-02-20 16:00:13 +00:00 |
|
Miroslav Stampar
|
2f9227bcce
|
Sybase update (--passwords)
|
2011-02-20 12:07:32 +00:00 |
|
Miroslav Stampar
|
f30dea74f3
|
more Sybase updates
|
2011-02-19 18:36:26 +00:00 |
|
Miroslav Stampar
|
b71bb321dd
|
some more Sybase updates
|
2011-02-19 18:04:27 +00:00 |
|
Miroslav Stampar
|
cec7694aac
|
some progress regarding SYBASE
|
2011-02-19 14:56:58 +00:00 |
|
Miroslav Stampar
|
e0efe453ab
|
minor update regarding Sybase support
|
2011-02-19 14:07:08 +00:00 |
|
Miroslav Stampar
|
de7ca5a27c
|
minor update
|
2011-02-19 09:40:41 +00:00 |
|
Miroslav Stampar
|
72fc0a0565
|
minor refactoring
|
2011-02-19 09:36:57 +00:00 |
|
Miroslav Stampar
|
5f4ffc9287
|
update regarding Sybase dumping
|
2011-02-19 00:36:47 +00:00 |
|
Miroslav Stampar
|
199f14df46
|
implementation of MySQL GROUP_CONCAT technique
|
2011-02-15 00:28:27 +00:00 |
|
Bernardo Damele
|
c078de894f
|
Added support for --privileges on MSSQL to test wheter or not the DBMS users are DBA
|
2011-02-10 14:24:04 +00:00 |
|
Bernardo Damele
|
a2c20acf94
|
Minor fixes once more
|
2011-02-10 11:34:16 +00:00 |
|
Miroslav Stampar
|
7539881ffa
|
fix for dump on Oracle but we still need to discuss some things around
|
2011-02-09 14:52:07 +00:00 |
|
Miroslav Stampar
|
caf6220c53
|
done with implementation for retrieving table names via access system table(s)
|
2011-02-09 10:50:38 +00:00 |
|
Miroslav Stampar
|
5050a76b59
|
update regarding reading of table names from access system tables
|
2011-02-09 10:33:29 +00:00 |
|
Miroslav Stampar
|
14c87ec80d
|
minor fix
|
2011-02-04 13:29:02 +00:00 |
|
Bernardo Damele
|
e3a3ae11cc
|
Proper return from error-based technique enumeration
|
2011-01-31 21:13:29 +00:00 |
|
Bernardo Damele
|
9fc0bedea8
|
Minor bug fixes
|
2011-01-30 21:01:57 +00:00 |
|
Miroslav Stampar
|
367d0639f0
|
refactoring (class names should always be Capital cased)
|
2011-01-28 16:36:09 +00:00 |
|
Bernardo Damele
|
77999fb39d
|
Allow in --sql-shell to always ('a') retrieve query output.
Minor bug fix in case with --columns it is not possible to retrieve a column datatype.
|
2011-01-20 21:49:06 +00:00 |
|
Bernardo Damele
|
bade0e3124
|
Major code refactoring - centralized all kb.dbms* info for both retrieval and set.
|
2011-01-19 23:06:15 +00:00 |
|