Bernardo Damele
|
8bdb7ec58c
|
Ahead with UNION exploitation after UNION test moved to detection phase - a lot to do yet.
|
2011-01-12 00:47:39 +00:00 |
|
Bernardo Damele
|
06230e4d92
|
Minor code refactoring and cosmetics
|
2011-01-11 21:46:21 +00:00 |
|
Miroslav Stampar
|
0676b38063
|
revert of one thing for Bernardo and minor update
|
2011-01-10 10:30:17 +00:00 |
|
Miroslav Stampar
|
8e83a26acf
|
minor fix
|
2011-01-07 17:53:17 +00:00 |
|
Bernardo Damele
|
cc46940159
|
Minor refactoring
|
2011-01-07 17:10:32 +00:00 |
|
Miroslav Stampar
|
b313a20a3f
|
some fixes
|
2011-01-07 16:39:47 +00:00 |
|
Bernardo Damele
|
16a06117f7
|
Mere cosmetics
|
2011-01-07 16:36:32 +00:00 |
|
Miroslav Stampar
|
8a48baf789
|
update for a "problem" reported by nightman@email.de where he lost all of large dumped table because in the middle of dumping 401 was raised
|
2011-01-04 13:23:59 +00:00 |
|
Miroslav Stampar
|
b763feafd9
|
bug fix (TypeError: object of type 'NoneType' has no len())
|
2011-01-02 12:26:31 +00:00 |
|
Miroslav Stampar
|
f0dad2a1e4
|
minor bug fix (in multiple item search only last item was shown)
|
2011-01-02 12:23:36 +00:00 |
|
Miroslav Stampar
|
7b9d978cf9
|
minor fix (database and/or table names with - sign inside needs to be escaped by ` character or will lead to a "SQL syntax")
|
2011-01-02 11:01:20 +00:00 |
|
Miroslav Stampar
|
e28b9f26fc
|
minor fix
|
2011-01-02 08:01:01 +00:00 |
|
Miroslav Stampar
|
7ea3d060f6
|
some fixes/updates here and there
|
2011-01-01 12:41:51 +00:00 |
|
Miroslav Stampar
|
6f17e84e19
|
minor fix
|
2010-12-30 08:29:20 +00:00 |
|
Miroslav Stampar
|
a77b186aca
|
minor fix
|
2010-12-27 16:55:27 +00:00 |
|
Miroslav Stampar
|
5015f04826
|
minor update
|
2010-12-27 16:36:05 +00:00 |
|
Miroslav Stampar
|
9c1676bdfa
|
minor cosmetics
|
2010-12-27 14:44:00 +00:00 |
|
Miroslav Stampar
|
9fb0e0fc85
|
resume of brute forced data is now available
|
2010-12-27 14:17:20 +00:00 |
|
Miroslav Stampar
|
3d23f226ae
|
minor update
|
2010-12-27 11:47:50 +00:00 |
|
Miroslav Stampar
|
68462466f2
|
minor fix for a bug reported by shaohua pan (argument of type 'NoneType' is not iterable)
|
2010-12-27 11:36:36 +00:00 |
|
Miroslav Stampar
|
51a492e17d
|
pretty important commit (now dumped tables are prone to dictionary attack)
|
2010-12-27 10:56:28 +00:00 |
|
Miroslav Stampar
|
c8d5a6b980
|
update
|
2010-12-27 00:41:16 +00:00 |
|
Miroslav Stampar
|
89c2640d23
|
basic --search now works with MS Access
|
2010-12-26 23:50:16 +00:00 |
|
Miroslav Stampar
|
c4d6a367e9
|
this way order given in -C is preserved
|
2010-12-26 14:11:42 +00:00 |
|
Miroslav Stampar
|
c93f2a703d
|
minor update
|
2010-12-26 14:02:16 +00:00 |
|
Miroslav Stampar
|
e41acb6fc2
|
further ms access improvements
|
2010-12-26 02:13:56 +00:00 |
|
Miroslav Stampar
|
2c8115eed9
|
further improvement for ms access table dumping
|
2010-12-26 01:04:30 +00:00 |
|
Miroslav Stampar
|
5249762794
|
update
|
2010-12-25 16:46:33 +00:00 |
|
Miroslav Stampar
|
fb099615e2
|
minor update
|
2010-12-25 11:16:35 +00:00 |
|
Miroslav Stampar
|
6845d402fa
|
well, here and there, merry Christmas to all :)
|
2010-12-24 20:17:53 +00:00 |
|
Miroslav Stampar
|
706d8e0b88
|
development update (basic ms access dumping implemented)
|
2010-12-24 19:53:11 +00:00 |
|
Miroslav Stampar
|
7c06dbffc3
|
bug fix (AttributeError: 'unicode' object has no attribute 'sort')
|
2010-12-22 18:55:50 +00:00 |
|
Bernardo Damele
|
b3da473840
|
Minor bug fix when --dbs has only one DB name
|
2010-12-22 14:29:57 +00:00 |
|
Bernardo Damele
|
c9ab8ae60e
|
Bug fix to properly identify if current user is DBA (--is-dba) on MySQL
|
2010-12-22 14:06:01 +00:00 |
|
Miroslav Stampar
|
c89021f0bb
|
some fixes
|
2010-12-22 11:46:18 +00:00 |
|
Miroslav Stampar
|
385e208f38
|
code refactoring regarding standard output suppression and some threading issues
|
2010-12-21 14:21:24 +00:00 |
|
Miroslav Stampar
|
6b37ddada4
|
removed some blank trailing spaces (with extra/shutils/blanks.sh)
|
2010-12-21 10:31:56 +00:00 |
|
Miroslav Stampar
|
36862e2efa
|
update
|
2010-12-18 15:57:47 +00:00 |
|
Miroslav Stampar
|
a067e805fa
|
minor update
|
2010-12-17 22:23:01 +00:00 |
|
Miroslav Stampar
|
e98d9c08e1
|
dumping table is now possible on Firebird too
|
2010-12-12 14:38:07 +00:00 |
|
Miroslav Stampar
|
b1babeefe5
|
update regarding dumping of tables with blind on Sqlite
|
2010-12-11 22:00:16 +00:00 |
|
Miroslav Stampar
|
b02bd55edc
|
minor refactoring
|
2010-12-10 13:04:36 +00:00 |
|
Miroslav Stampar
|
5764816891
|
minor cosmetics
|
2010-12-03 22:28:09 +00:00 |
|
Miroslav Stampar
|
2cc167a42e
|
fix for a bug reported by ToR: "AttributeError: 'NoneType' object has no attribute 'isdigit'"
|
2010-12-02 18:57:43 +00:00 |
|
Bernardo Damele
|
c22338ce90
|
Removed --error-test, --stacked-test and --time-test switches and adapted the code accordingly. This is due to the fact that the new XML based detection engine already supports all of those tests (and more).
|
2010-11-29 11:47:58 +00:00 |
|
Miroslav Stampar
|
ba4ea32603
|
first working version of dictionary attack
|
2010-11-23 13:24:02 +00:00 |
|
Bernardo Damele
|
a34c1b287c
|
Bug fix related to properly identify and parse the version from the banner (used for --stacked-test and other matters on MySQL/PgSQL)
|
2010-11-12 11:33:11 +00:00 |
|
Miroslav Stampar
|
42272ca78c
|
minor update
|
2010-11-11 22:26:36 +00:00 |
|
Miroslav Stampar
|
be992b4471
|
update regarding common columns existance check
|
2010-11-11 17:09:31 +00:00 |
|
Miroslav Stampar
|
4be0631161
|
refactoring of brute force techniques
|
2010-11-09 09:42:43 +00:00 |
|