| 
							
							
								 Miroslav Stampar | 458a73c9b4 | few consistency fixes | 2012-04-29 23:09:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 694b14111f | skipping suffix if comment is used in agent.suffixQuery (and --suffix not explicitly set) | 2012-04-27 13:16:51 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c7a606637f | switching few readInput defaults for brute forcing when no table/column found | 2012-04-27 12:59:22 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1e45ee9ab6 | reverting back to smaller UNION ranges as that mechanism for automatic extending was implemented few days ago | 2012-04-25 20:37:39 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6f67dc85ee | adding --invalid-bignum (Havij like bignum style for invalidating/negating values); renaming --logical-negate to --invalid-logical | 2012-04-25 20:29:07 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 4da03d898e | Added support to create files with a visual basic script - no longer reliant on debug.exe so works on Windows 64-bit too. Fixes #236 | 2012-04-25 07:40:42 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 6116853025 | Minor layout adjustments | 2012-04-24 17:01:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cec432f94d | minor update | 2012-04-23 14:43:59 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 697768c01a | adding --purge-output to be one of mandatory switches | 2012-04-23 14:42:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d57d5e4b2c | minor update | 2012-04-23 14:33:36 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1eecfb3dce | adding new file related to the last commit | 2012-04-23 14:25:16 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 095b25e1d1 | adding option '--purge' | 2012-04-23 14:24:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3532d23933 | automatically extending ranges for UNION tests in case where at least one other injection technique is usable (boundaries has been established) | 2012-04-23 13:41:36 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | eb73cab636 | increased UNION test ranges | 2012-04-23 11:54:52 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | be2da77bf8 | minor update | 2012-04-23 10:15:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 21c6b52198 | minor fix | 2012-04-23 10:11:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 775134639d | minor update | 2012-04-20 20:33:15 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 072e08836f | Falling back to unionReadFile() when --file-read does not work against MySQL. This happens when the session user does not have INSERT privilege, required to run LOAD DATA INFILE | 2012-04-19 14:05:45 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2b1b4c0742 | minor fix | 2012-04-18 10:01:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6ebb621228 | adding support for (custom) POST injection (marking injection point with '*' in conf.data) | 2012-04-17 14:23:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | efd27d7ade | minor renaming | 2012-04-17 08:41:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ccd6fb70a8 | minor refactoring | 2012-04-15 17:17:30 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 965c1511a6 | adding new tamper script | 2012-04-15 17:10:43 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 601d118c68 | reverting back to UNION ALL scheme (UNION is doing another DISTINCT on data causing problems on some column types) | 2012-04-15 16:59:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 71b0acc16f | minor fix (checking for full inband should be done with ORIGINAL - more concise) | 2012-04-15 16:43:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5772c52f46 | minor refactoring/fix (randQuery is just a part (e.g. abc) of phrase (def🔤ghi) - phrase should be searched for, not just randQuery); both phrases should be inside the content for it to be full-inband injectable (...UNION ALL SELECT phrase UNION ALL SELECT phrase2....) | 2012-04-15 16:33:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ae8c70e895 | another cosmetics | 2012-04-13 15:11:44 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d765cdc3a3 | minor cosmetics | 2012-04-13 15:10:40 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 54576ab3a6 | making a random choice from candidates | 2012-04-13 10:54:30 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | bbbcc95fe5 | use it only if page is stable | 2012-04-13 10:19:26 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 414c74b8aa | new payload | 2012-04-13 08:16:33 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 052d9455fe | warning user in cases of "User xyz already has more than 'max_user_connections' active connections" | 2012-04-12 09:44:54 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 831f79b851 | minor generalization | 2012-04-12 09:30:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c7422546e1 | tiny update | 2012-04-11 23:01:38 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2bad73a981 | minor update | 2012-04-11 21:48:44 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e195de2093 | correcting comment on reflective removal function | 2012-04-11 21:41:48 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b45ae10da4 | minor fixes | 2012-04-11 21:36:37 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 627bfc589f | some more updates in reflective removal mechanism | 2012-04-11 21:26:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8b130f6497 | minor improvement for reflective values (when missing first part of payload like in error reports) | 2012-04-11 15:01:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 01bd5d0ab2 | some more updates for reflective mechanism | 2012-04-11 10:41:33 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2e92d8636e | improvement of reflective mechanism | 2012-04-11 08:58:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 60ca44e0cf | minor adjustment | 2012-04-11 08:35:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e33ea7c33a | minor fix | 2012-04-10 22:29:39 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8541222080 | minor update | 2012-04-10 22:26:42 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9c2f244d47 | minor fix | 2012-04-10 22:20:53 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a82206cec4 | minor cosmetics | 2012-04-10 21:57:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 119eec3598 | improving "boolean detection" by automatic recognition of convenient --string candidate | 2012-04-10 21:48:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 698b7a15d9 | minor update | 2012-04-07 14:14:26 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8c6eb4faa9 | adding support for PgSQL DNS data exfiltration | 2012-04-07 14:06:11 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b2afa87e48 | reading page responses in chunks, trimming unnecessary content (especially for large table dumps in full inband cases) | 2012-04-06 08:42:36 +00:00 |  |