Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							dac59a55bc 
							
						 
					 
					
						
						
							
							leftover  
						
						
						
					 
					
						2011-05-03 14:14:39 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							c58dc4a6d8 
							
						 
					 
					
						
						
							
							isDbmsWithin() must stay like this, no getIdentifiedDbms() in there  
						
						
						
					 
					
						2011-05-03 14:13:45 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							eceb5eca7b 
							
						 
					 
					
						
						
							
							fix for --file-read on MSSQL for error technique (again that unpacking was causing problems); also reverting that check for file paths as one user mentioned that network paths are also possible for usage on Windows machines (e.g. \\bla\bla)  
						
						
						
					 
					
						2011-05-02 21:55:06 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							b327a78522 
							
						 
					 
					
						
						
							
							minor minor update of the last commit  
						
						
						
					 
					
						2011-05-02 19:24:49 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							0bb7d715a7 
							
						 
					 
					
						
						
							
							more user friendliness/handiness for users which mix Linux and Windows paths where they shouldn't do that  
						
						
						
					 
					
						2011-05-02 19:18:28 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							8e8886cd20 
							
						 
					 
					
						
						
							
							minor improvement for --sql-shell/--sql-query (when non-SELECT default is N for retrieve data output which automatically does STACKED injection)  
						
						
						
					 
					
						2011-05-01 21:41:14 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							64bb480414 
							
						 
					 
					
						
						
							
							Do not raise otherwise it won't work with --schema  
						
						
						
					 
					
						2011-04-30 23:20:16 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							d5eeb91b35 
							
						 
					 
					
						
						
							
							Aligned Sybase and MaxDB to recent enhancements to --dbs, --tables and --columns  
						
						
						
					 
					
						2011-04-30 22:11:36 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							b31b861d7b 
							
						 
					 
					
						
						
							
							Major rewrote of --columns: now it accepts -D only (enumerate all tables' columns of a specific database), -D and -T (enumerate all columns of a specific database's table), -T (enumerate all columns of a current database's table), etc.  
						
						
						
					 
					
						2011-04-30 22:10:27 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							284c69a686 
							
						 
					 
					
						
						
							
							Improved --tables for MSSQL too, like r3798  
						
						
						
					 
					
						2011-04-30 22:05:02 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							aeb149db22 
							
						 
					 
					
						
						
							
							Proper ordering of enumeration methods, consistent with the others enumeration classes  
						
						
						
					 
					
						2011-04-30 22:04:08 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							955dbc85e7 
							
						 
					 
					
						
						
							
							Minor variable rename  
						
						
						
					 
					
						2011-04-30 15:29:59 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							cb9b9c4204 
							
						 
					 
					
						
						
							
							Code refactoring and improvements to --dbs and --tables: now --tables accepts also -D CD as an alias for Current Database and as usual multiple database comma-separated are supported too  
						
						
						
					 
					
						2011-04-30 15:29:19 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							b3a0424269 
							
						 
					 
					
						
						
							
							More Backend class method usage refactoring  
						
						
						
					 
					
						2011-04-30 15:24:15 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							9a4ae7d9e2 
							
						 
					 
					
						
						
							
							More code refactoring of Backend class methods used  
						
						
						
					 
					
						2011-04-30 14:54:29 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							36a9ddaacc 
							
						 
					 
					
						
						
							
							Minor bug fixes and code restyling for --privileges and --passwords  
						
						
						
					 
					
						2011-04-30 14:50:27 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							f56d135438 
							
						 
					 
					
						
						
							
							Minor code restyling  
						
						
						
					 
					
						2011-04-30 13:20:05 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							1a052245a6 
							
						 
					 
					
						
						
							
							duplicate code  
						
						
						
					 
					
						2011-04-30 00:25:15 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							a5968fff3e 
							
						 
					 
					
						
						
							
							Added --count switch to count the number of entries for a specific table (when -T is provided), all database's tables (when only -D is provided) or all databases' tables when neither -D nor -T are provided  
						
						
						
					 
					
						2011-04-30 00:22:22 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							529595fd85 
							
						 
					 
					
						
						
							
							Moved method below  
						
						
						
					 
					
						2011-04-29 22:37:43 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							14bf6abb7e 
							
						 
					 
					
						
						
							
							Minor layout adjustment  
						
						
						
					 
					
						2011-04-29 21:40:48 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							f449688f93 
							
						 
					 
					
						
						
							
							Proper resume of --schema data when calling with --columns switch, minor fixes too  
						
						
						
					 
					
						2011-04-29 21:17:59 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							a6015b59df 
							
						 
					 
					
						
						
							
							fix for a bug reported by jaccovantuijl@gmail.com (entries = zip(*[entries[colName] for colName in colList]))  
						
						
						
					 
					
						2011-04-29 14:33:47 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							9927f5a7db 
							
						 
					 
					
						
						
							
							Let --schema work also for Sybase and MaxDB  
						
						
						
					 
					
						2011-04-29 00:02:28 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							edac0b2558 
							
						 
					 
					
						
						
							
							Added switch --schema to enumerate DBMS schema and now --columns does not require a mandatory table (-T) anymore, instead it will act as an alias for --schema  
						
						
						
					 
					
						2011-04-28 23:59:00 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							e35f25b2cb 
							
						 
					 
					
						
						
							
							Major recode of --os-pwn functionality. Now the Metasploit shellcode can not be run as a Metasploit generated payload stager anymore. Instead it can be run on the target system either via sys_bineval() (as it was before, anti-forensics mode, all the same) or via shellcodeexec executable. Advantages are that:  
						
						... 
						
						
						
						* It is stealthier as the shellcode itself does not touch the filesystem, it's an argument passed to shellcodeexec at runtime.
* shellcodeexec is not (yet) recognized as malicious by any (Avast excluded) AV product.
* shellcodeexec binary size is significantly smaller than a Metasploit payload stager (even when packed with UPX).
* UPX now is not needed anymore, so sqlmap package is also way smaller and less likely to be detected itself as malicious by your AV software.
shellcodeexec source code, compilation files and binaries are in extra/shellcodeexec/ folder now - copied over from https://github.com/inquisb/shellcodeexec .
Minor code refactoring. 
						
					 
					
						2011-04-24 23:01:21 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							d0a534dee5 
							
						 
					 
					
						
						
							
							Do not even prompt for ICMP tunnel if the target OS is not Windows  
						
						
						
					 
					
						2011-04-23 21:57:07 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							d0dff82ce0 
							
						 
					 
					
						
						
							
							Minor code refactoring relating set/get back-end DBMS operating system and minor bug fix to properly enforce OS value with --os switch  
						
						
						
					 
					
						2011-04-23 16:25:09 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							148fb26301 
							
						 
					 
					
						
						
							
							quick fix  
						
						
						
					 
					
						2011-04-21 17:34:26 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							e181d5412e 
							
						 
					 
					
						
						
							
							fix for a bug reported by aboynes@gmail.com (@@datadir not available on MySQL 4)  
						
						
						
					 
					
						2011-04-21 17:33:07 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							bd4fbb3251 
							
						 
					 
					
						
						
							
							fix for a bug reported by l0rda@l0rda.biz (TypeError: cannot concatenate 'str' and 'NoneType' objects)  
						
						
						
					 
					
						2011-04-21 14:53:02 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							5052013ffa 
							
						 
					 
					
						
						
							
							minor update  
						
						
						
					 
					
						2011-04-20 14:48:23 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							f909ecb369 
							
						 
					 
					
						
						
							
							bug fix for mssqlserver escape  
						
						
						
					 
					
						2011-04-20 13:41:01 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							88c76147e1 
							
						 
					 
					
						
						
							
							removed few trailing whitespace lines  
						
						
						
					 
					
						2011-04-15 20:52:08 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							c16b74ce1a 
							
						 
					 
					
						
						
							
							covering __pivotDumpTable for keyboard and connection exceptions too  
						
						
						
					 
					
						2011-04-15 14:21:13 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							0387654166 
							
						 
					 
					
						
						
							
							update of copyright string (until year)  
						
						
						
					 
					
						2011-04-15 12:33:18 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							aed994192e 
							
						 
					 
					
						
						
							
							disabling safecharencode for --banner  
						
						
						
					 
					
						2011-04-15 08:15:21 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							8ddac7fe5a 
							
						 
					 
					
						
						
							
							minor fix and speedup when pivoting empty table  
						
						
						
					 
					
						2011-04-14 21:11:20 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							384ca98ded 
							
						 
					 
					
						
						
							
							don't let sqlmapNoneDataException for one table to break whole dumpAll()  
						
						
						
					 
					
						2011-04-14 20:56:12 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							dbbaefa79d 
							
						 
					 
					
						
						
							
							minor update (pivot value should be safechardecoded)  
						
						
						
					 
					
						2011-04-14 20:38:03 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							d06ae9cd47 
							
						 
					 
					
						
						
							
							implemented retrieved items info for partial union too  
						
						
						
					 
					
						2011-04-13 14:33:15 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							1c51e11c5c 
							
						 
					 
					
						
						
							
							Minor adjustments to PgSQL fingerprint  
						
						
						
					 
					
						2011-04-12 10:35:33 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							7324d53997 
							
						 
					 
					
						
						
							
							reference ( http://www.enterprisedb.com/docs/en/9.0/pg/release-9-0.html )  
						
						
						
					 
					
						2011-04-12 10:30:33 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							bc4c2f320c 
							
						 
					 
					
						
						
							
							cosmetics  
						
						
						
					 
					
						2011-04-12 10:24:09 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							2f1786e65f 
							
						 
					 
					
						
						
							
							added active fingerprint for pgsql >= 9.0.3 (reference:  http://www.postgresql.org/docs/9.0/static/release-9-0.html )  
						
						
						
					 
					
						2011-04-12 10:22:54 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							fdbd8bfe37 
							
						 
					 
					
						
						
							
							initial support for PostgreSQL 9.0 -  #223  
						
						
						
					 
					
						2011-04-11 22:02:00 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							f4745a95ea 
							
						 
					 
					
						
						
							
							Possible fix for bug reported by David  
						
						
						
					 
					
						2011-04-11 21:45:25 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							941daa1645 
							
						 
					 
					
						
						
							
							just in case to prevent "object of type 'NoneType' has no len()" error reports  
						
						
						
					 
					
						2011-04-11 11:59:02 +00:00 
						 
				 
			
				
					
						
							
							
								Miroslav Stampar 
							
						 
					 
					
						
						
						
						
							
						
						
							e20848c711 
							
						 
					 
					
						
						
							
							first commit toward v1.0 (it's smarter to start testing for pivot point from shorter column names as they tend to be some kind of identifiers)  
						
						
						
					 
					
						2011-04-11 09:40:52 +00:00 
						 
				 
			
				
					
						
							
							
								Bernardo Damele 
							
						 
					 
					
						
						
						
						
							
						
						
							ea3ebafba1 
							
						 
					 
					
						
						
							
							Removed outdated sentence  
						
						
						
					 
					
						2011-04-10 23:59:49 +00:00