Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							3532d23933
							
						
					 | 
					
						
						
							
							automatically extending ranges for UNION tests in case where at least one other injection technique is usable (boundaries has been established)
						
						
						
						
						
					 | 
					
						2012-04-23 13:41:36 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							be2da77bf8
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2012-04-23 10:15:04 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							21c6b52198
							
						
					 | 
					
						
						
							
							minor fix
						
						
						
						
						
					 | 
					
						2012-04-23 10:11:00 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							775134639d
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2012-04-20 20:33:15 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							2b1b4c0742
							
						
					 | 
					
						
						
							
							minor fix
						
						
						
						
						
					 | 
					
						2012-04-18 10:01:04 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							6ebb621228
							
						
					 | 
					
						
						
							
							adding support for (custom) POST injection (marking injection point with '*' in conf.data)
						
						
						
						
						
					 | 
					
						2012-04-17 14:23:00 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							efd27d7ade
							
						
					 | 
					
						
						
							
							minor renaming
						
						
						
						
						
					 | 
					
						2012-04-17 08:41:19 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							601d118c68
							
						
					 | 
					
						
						
							
							reverting back to UNION ALL scheme (UNION is doing another DISTINCT on data causing problems on some column types)
						
						
						
						
						
					 | 
					
						2012-04-15 16:59:03 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							71b0acc16f
							
						
					 | 
					
						
						
							
							minor fix (checking for full inband should be done with ORIGINAL - more concise)
						
						
						
						
						
					 | 
					
						2012-04-15 16:43:18 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							5772c52f46
							
						
					 | 
					
						
						
							
							minor refactoring/fix (randQuery is just a part (e.g. abc) of phrase (def🔤ghi) - phrase should be searched for, not just randQuery); both phrases should be inside the content for it to be full-inband injectable (...UNION ALL SELECT phrase UNION ALL SELECT phrase2....)
						
						
						
						
						
					 | 
					
						2012-04-15 16:33:47 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							ae8c70e895
							
						
					 | 
					
						
						
							
							another cosmetics
						
						
						
						
						
					 | 
					
						2012-04-13 15:11:44 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							d765cdc3a3
							
						
					 | 
					
						
						
							
							minor cosmetics
						
						
						
						
						
					 | 
					
						2012-04-13 15:10:40 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							54576ab3a6
							
						
					 | 
					
						
						
							
							making a random choice from candidates
						
						
						
						
						
					 | 
					
						2012-04-13 10:54:30 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							bbbcc95fe5
							
						
					 | 
					
						
						
							
							use it only if page is stable
						
						
						
						
						
					 | 
					
						2012-04-13 10:19:26 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							052d9455fe
							
						
					 | 
					
						
						
							
							warning user in cases of "User xyz already has more than 'max_user_connections' active connections"
						
						
						
						
						
					 | 
					
						2012-04-12 09:44:54 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							831f79b851
							
						
					 | 
					
						
						
							
							minor generalization
						
						
						
						
						
					 | 
					
						2012-04-12 09:30:19 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							c7422546e1
							
						
					 | 
					
						
						
							
							tiny update
						
						
						
						
						
					 | 
					
						2012-04-11 23:01:38 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							2bad73a981
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2012-04-11 21:48:44 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							e195de2093
							
						
					 | 
					
						
						
							
							correcting comment on reflective removal function
						
						
						
						
						
					 | 
					
						2012-04-11 21:41:48 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							b45ae10da4
							
						
					 | 
					
						
						
							
							minor fixes
						
						
						
						
						
					 | 
					
						2012-04-11 21:36:37 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							627bfc589f
							
						
					 | 
					
						
						
							
							some more updates in reflective removal mechanism
						
						
						
						
						
					 | 
					
						2012-04-11 21:26:00 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							8b130f6497
							
						
					 | 
					
						
						
							
							minor improvement for reflective values (when missing first part of payload like in error reports)
						
						
						
						
						
					 | 
					
						2012-04-11 15:01:28 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							01bd5d0ab2
							
						
					 | 
					
						
						
							
							some more updates for reflective mechanism
						
						
						
						
						
					 | 
					
						2012-04-11 10:41:33 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							2e92d8636e
							
						
					 | 
					
						
						
							
							improvement of reflective mechanism
						
						
						
						
						
					 | 
					
						2012-04-11 08:58:03 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							60ca44e0cf
							
						
					 | 
					
						
						
							
							minor adjustment
						
						
						
						
						
					 | 
					
						2012-04-11 08:35:09 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							e33ea7c33a
							
						
					 | 
					
						
						
							
							minor fix
						
						
						
						
						
					 | 
					
						2012-04-10 22:29:39 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							8541222080
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2012-04-10 22:26:42 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							9c2f244d47
							
						
					 | 
					
						
						
							
							minor fix
						
						
						
						
						
					 | 
					
						2012-04-10 22:20:53 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							a82206cec4
							
						
					 | 
					
						
						
							
							minor cosmetics
						
						
						
						
						
					 | 
					
						2012-04-10 21:57:00 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							119eec3598
							
						
					 | 
					
						
						
							
							improving "boolean detection" by automatic recognition of convenient --string candidate
						
						
						
						
						
					 | 
					
						2012-04-10 21:48:34 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							8c6eb4faa9
							
						
					 | 
					
						
						
							
							adding support for PgSQL DNS data exfiltration
						
						
						
						
						
					 | 
					
						2012-04-07 14:06:11 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							b2afa87e48
							
						
					 | 
					
						
						
							
							reading page responses in chunks, trimming unnecessary content (especially for large table dumps in full inband cases)
						
						
						
						
						
					 | 
					
						2012-04-06 08:42:36 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							2223c884e5
							
						
					 | 
					
						
						
							
							minor refactoring
						
						
						
						
						
					 | 
					
						2012-04-05 12:55:26 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							02924eb345
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2012-04-04 23:47:06 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							e0994947e2
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2012-04-04 23:37:50 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							b1dd03731a
							
						
					 | 
					
						
						
							
							minor cosmetics
						
						
						
						
						
					 | 
					
						2012-04-04 23:34:08 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							83387d92bb
							
						
					 | 
					
						
						
							
							minor bug fix
						
						
						
						
						
					 | 
					
						2012-04-04 23:32:20 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							c89a4162e2
							
						
					 | 
					
						
						
							
							bug fix for --dns-domain with --technique=TS
						
						
						
						
						
					 | 
					
						2012-04-04 18:01:39 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							098c7c06dd
							
						
					 | 
					
						
						
							
							added few comments
						
						
						
						
						
					 | 
					
						2012-04-04 13:24:58 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							a5b69eaea4
							
						
					 | 
					
						
						
							
							removing unused imports
						
						
						
						
						
					 | 
					
						2012-04-04 13:18:14 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							52796bb4da
							
						
					 | 
					
						
						
							
							revert
						
						
						
						
						
					 | 
					
						2012-04-04 13:02:50 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							a4b95ab7dd
							
						
					 | 
					
						
						
							
							works against MySQL/Windows
						
						
						
						
						
					 | 
					
						2012-04-04 12:49:45 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							a1d97e9d7b
							
						
					 | 
					
						
						
							
							Add a space after a comment
						
						
						
						
						
					 | 
					
						2012-04-04 12:48:21 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							025c531d22
							
						
					 | 
					
						
						
							
							leftover
						
						
						
						
						
					 | 
					
						2012-04-04 12:44:25 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							c0946ce2c9
							
						
					 | 
					
						
						
							
							Minor refactoring
						
						
						
						
						
					 | 
					
						2012-04-04 12:42:58 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							75d1dab895
							
						
					 | 
					
						
						
							
							more cosmetics
						
						
						
						
						
					 | 
					
						2012-04-04 12:33:16 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							d106fb5184
							
						
					 | 
					
						
						
							
							layout adjustments
						
						
						
						
						
					 | 
					
						2012-04-04 12:27:24 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							1b2cd44255
							
						
					 | 
					
						
						
							
							proper fix
						
						
						
						
						
					 | 
					
						2012-04-04 10:35:52 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							7031ef8e00
							
						
					 | 
					
						
						
							
							removing default values for referer and host from higher level/risk options
						
						
						
						
						
					 | 
					
						2012-04-04 10:34:27 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							5e358b51f9
							
						
					 | 
					
						
						
							
							few fixes related to bug report by Shadow Folder (AttributeError: 'list' object has no attribute 'isdigit')
						
						
						
						
						
					 | 
					
						2012-04-04 09:25:05 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							5851badff1
							
						
					 | 
					
						
						
							
							minor refactoring
						
						
						
						
						
					 | 
					
						2012-04-03 14:46:09 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							b0787f193c
							
						
					 | 
					
						
						
							
							getting rid of obsolete getCompiledRegex (in newer versions of Python regexes are already cached)
						
						
						
						
						
					 | 
					
						2012-04-03 14:34:15 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							556b349be3
							
						
					 | 
					
						
						
							
							minor fix for retrieving non-printable chars in inference and non-multi threading mode
						
						
						
						
						
					 | 
					
						2012-04-03 14:04:07 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							33bb9c5f19
							
						
					 | 
					
						
						
							
							much cleaner approach in that "flat" representation of retrieved items in union technique
						
						
						
						
						
					 | 
					
						2012-04-03 13:56:11 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							7fb190f3b1
							
						
					 | 
					
						
						
							
							minor fix
						
						
						
						
						
					 | 
					
						2012-04-03 12:35:19 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							886aa22efc
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2012-04-03 12:19:37 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							503988887c
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2012-04-03 10:43:46 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							78f51fd2e5
							
						
					 | 
					
						
						
							
							minor fix
						
						
						
						
						
					 | 
					
						2012-04-03 10:18:03 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							2504f4edb8
							
						
					 | 
					
						
						
							
							minor fixes
						
						
						
						
						
					 | 
					
						2012-04-03 10:10:33 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							e05109812f
							
						
					 | 
					
						
						
							
							minor improvements regarding data retrieval through DNS channel
						
						
						
						
						
					 | 
					
						2012-04-03 09:18:30 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							5f94987b0f
							
						
					 | 
					
						
						
							
							fix for DNS method for MSSQL
						
						
						
						
						
					 | 
					
						2012-04-02 17:28:18 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							2c28423cb8
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2012-04-02 14:57:15 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							8a9d09f79b
							
						
					 | 
					
						
						
							
							minor fixes
						
						
						
						
						
					 | 
					
						2012-04-02 14:11:23 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							1cd3c3f7af
							
						
					 | 
					
						
						
							
							further update of DNS data retrieval mechanism through SQLi
						
						
						
						
						
					 | 
					
						2012-04-02 14:05:30 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							1e01203562
							
						
					 | 
					
						
						
							
							few just in case "patches"
						
						
						
						
						
					 | 
					
						2012-04-02 12:58:10 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							d908d078dd
							
						
					 | 
					
						
						
							
							minor fix
						
						
						
						
						
					 | 
					
						2012-04-02 12:27:30 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							abffc39929
							
						
					 | 
					
						
						
							
							minor update regarding DNS data retrieval task
						
						
						
						
						
					 | 
					
						2012-04-02 12:22:40 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							f7a664b120
							
						
					 | 
					
						
						
							
							enablind DNS server for DNS data exfiltration
						
						
						
						
						
					 | 
					
						2012-03-31 12:08:27 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							8be9cd4ac4
							
						
					 | 
					
						
						
							
							bug fix (on Linux machine when os.geteuid() returns an integer value !=0 it was then returned and interpreted as TRUE value)
						
						
						
						
						
					 | 
					
						2012-03-31 10:22:50 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							429b8396e9
							
						
					 | 
					
						
						
							
							minor update for DNSServer support
						
						
						
						
						
					 | 
					
						2012-03-30 13:20:29 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							56638f9e95
							
						
					 | 
					
						
						
							
							making --no-cast unhidden and renaming --negative-logic to --logical-negate to prevent confusion with stuff used in OR boolean based injection
						
						
						
						
						
					 | 
					
						2012-03-30 10:50:01 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							79c3d6f2aa
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2012-03-30 10:37:46 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							6acf6b193a
							
						
					 | 
					
						
						
							
							minor update regarding boolean logic comparison mechanism
						
						
						
						
						
					 | 
					
						2012-03-30 09:42:58 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							5469186540
							
						
					 | 
					
						
						
							
							minor comment update
						
						
						
						
						
					 | 
					
						2012-03-29 14:35:47 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							637a8d8273
							
						
					 | 
					
						
						
							
							improvement toward proper implementation of OR-based injection by usage of "negative logic" mechanism
						
						
						
						
						
					 | 
					
						2012-03-29 14:33:27 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							ce4c697bbd
							
						
					 | 
					
						
						
							
							disabling "negative logic" as it's not half done (it was "luckily" working for --string/--regex/--code but it was a sheer luck); removing "dirty fix" from checks.py; proof that this was not ready for the release is that there was not check for negative logic anywhere for anything more then --string/--regex/--code
						
						
						
						
						
					 | 
					
						2012-03-29 13:39:12 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							772ead8d03
							
						
					 | 
					
						
						
							
							fixed support for error-based injection on MySQL 4.1 (help table a needs more than 2 items inside); also, fixed some border issues with reflective values
						
						
						
						
						
					 | 
					
						2012-03-29 12:44:20 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							c9cac957bb
							
						
					 | 
					
						
						
							
							adding one more case for false positive check (Generic tests without any DBMS knowledge)
						
						
						
						
						
					 | 
					
						2012-03-29 09:56:09 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							60146481af
							
						
					 | 
					
						
						
							
							bug fix(es) (flags were used in place of count parameter in re.sub() calls)
						
						
						
						
						
					 | 
					
						2012-03-28 19:33:00 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							9433bbe26d
							
						
					 | 
					
						
						
							
							memory optimization for reflective removal mechanism (there was no need for \n\r in the first place as there was no re.S flag used - also, one re.sub "flags <-> count" bug fixed)
						
						
						
						
						
					 | 
					
						2012-03-28 19:27:12 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							7d131d1fb1
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2012-03-28 13:46:31 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							7fd64df167
							
						
					 | 
					
						
						
							
							minor code cleaning
						
						
						
						
						
					 | 
					
						2012-03-28 13:31:07 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							769b0d0ae7
							
						
					 | 
					
						
						
							
							more minor updates regarding data retrieval through DNS channel
						
						
						
						
						
					 | 
					
						2012-03-27 19:29:24 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							1b072f6415
							
						
					 | 
					
						
						
							
							laying foundation for DNS based data retrieval
						
						
						
						
						
					 | 
					
						2012-03-27 18:59:12 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							3abcd6910a
							
						
					 | 
					
						
						
							
							strange combination of "Set-Cookie" and interleaved pattern of True/False like responses can result in bypassing of the ABAB test
						
						
						
						
						
					 | 
					
						2012-03-22 00:06:50 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							e88687b1f0
							
						
					 | 
					
						
						
							
							revert of last commit (it would be faster for sure, but not sure if it's clever to do it by default regarding SQLi detection)
						
						
						
						
						
					 | 
					
						2012-03-21 23:15:59 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							524c1d38ad
							
						
					 | 
					
						
						
							
							making default redirect choice to NO (making fewer requests by default and in lots of cases clearer pages for comparison - original page vs redirect message)
						
						
						
						
						
					 | 
					
						2012-03-21 23:03:57 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							11132ba993
							
						
					 | 
					
						
						
							
							fix for a bug in reflection removal mechanism
						
						
						
						
						
					 | 
					
						2012-03-19 14:28:18 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							8e7d360ea2
							
						
					 | 
					
						
						
							
							cleaner refactoring regarding last commit
						
						
						
						
						
					 | 
					
						2012-03-19 12:03:25 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							401763b6f8
							
						
					 | 
					
						
						
							
							minor fix (it has to be level 1 array like it was with the previous re.findall mechanism)
						
						
						
						
						
					 | 
					
						2012-03-19 12:00:22 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							037db9b3b8
							
						
					 | 
					
						
						
							
							minor removal of older stuff
						
						
						
						
						
					 | 
					
						2012-03-19 09:38:27 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							da7f4eeffd
							
						
					 | 
					
						
						
							
							removing left over
						
						
						
						
						
					 | 
					
						2012-03-18 17:33:14 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							0fc4288a7c
							
						
					 | 
					
						
						
							
							modifying redirection code for only two choices
						
						
						
						
						
					 | 
					
						2012-03-18 17:27:08 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							c03d0e24fb
							
						
					 | 
					
						
						
							
							it must stay as is
						
						
						
						
						
					 | 
					
						2012-03-16 17:42:00 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							3505503a08
							
						
					 | 
					
						
						
							
							no need to return here
						
						
						
						
						
					 | 
					
						2012-03-16 17:30:16 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							942d9e4fa8
							
						
					 | 
					
						
						
							
							code cleanup
						
						
						
						
						
					 | 
					
						2012-03-16 17:27:24 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							a1c943fc79
							
						
					 | 
					
						
						
							
							Major bug fix to comparison algorithm with OR based boolean-based injections
						
						
						
						
						
					 | 
					
						2012-03-16 17:22:55 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							d66056fe39
							
						
					 | 
					
						
						
							
							one more related commit
						
						
						
						
						
					 | 
					
						2012-03-16 13:16:53 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							ac02a2d92c
							
						
					 | 
					
						
						
							
							minor fix
						
						
						
						
						
					 | 
					
						2012-03-16 13:14:14 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							cbdcbdd786
							
						
					 | 
					
						
						
							
							minor minor update
						
						
						
						
						
					 | 
					
						2012-03-16 11:18:18 +00:00 | 
					
					
						
						
							
							
							
						
					 |