Miroslav Stampar
|
cccb565859
|
cosmetics
|
2010-11-16 14:11:32 +00:00 |
|
Miroslav Stampar
|
b9d9f18939
|
added General cmdline group
|
2010-11-16 14:09:09 +00:00 |
|
Miroslav Stampar
|
6ef3846400
|
update regarding error parsing (and reporting)
|
2010-11-16 10:42:42 +00:00 |
|
Bernardo Damele
|
8d07272c82
|
Added --union-cols switch to specify the max number of columns to test for UNION query sql injection.
Now stores/resumes also the exact UNION payload to session file.
|
2010-11-13 23:24:41 +00:00 |
|
Miroslav Stampar
|
24238ccd0b
|
re-renaming of brute force switches. this way is better.
|
2010-11-11 07:57:44 +00:00 |
|
Miroslav Stampar
|
a7fa8d4975
|
update regarding brute force retrieval of table names and table column names
|
2010-11-09 16:15:55 +00:00 |
|
Bernardo Damele
|
78d7b17483
|
More replacements for refactoring.
Minor layout adjustments.
Alignment of conffile/optiondict/cmdline parameters.
|
2010-11-08 12:36:48 +00:00 |
|
Miroslav Stampar
|
a3de10e3a2
|
new option -t
|
2010-11-08 11:22:47 +00:00 |
|
Miroslav Stampar
|
4e6d1b5118
|
added "Detection" part in help listing
|
2010-11-08 10:11:43 +00:00 |
|
Miroslav Stampar
|
862395ced1
|
further refactoring (all enumerations are now put into enums.py)
|
2010-11-08 09:20:02 +00:00 |
|
Bernardo Damele
|
b6da946883
|
Added one new verbose level, -v 3 now shows the full injected payload.
Fixed also -d verbose output.
|
2010-11-07 22:34:29 +00:00 |
|
Miroslav Stampar
|
00dfd55830
|
added powerful switch --longest-common for dealing with heavy dynamicity
|
2010-11-07 08:52:09 +00:00 |
|
Miroslav Stampar
|
685a8e7d2c
|
refactoring of hard coded dbms names
|
2010-11-02 11:59:24 +00:00 |
|
Miroslav Stampar
|
5a38ac7ea9
|
important update regarding (Bug #209) - probably more will be needed
|
2010-10-29 16:11:50 +00:00 |
|
Bernardo Damele
|
debaf2215f
|
Consistency between cmdline.py, optiondict.py and sqlmap.conf and got rid of --union-use switch
|
2010-10-25 15:54:45 +00:00 |
|
Miroslav Stampar
|
378653a1ec
|
added IDS payload testing
|
2010-10-25 15:37:43 +00:00 |
|
Bernardo Damele
|
bdb9c37a7e
|
Cosmetics
|
2010-10-25 15:17:59 +00:00 |
|
Miroslav Stampar
|
aa931efd4d
|
several MySQL fixes/enhancements pointed out by Anton Mogilin
|
2010-10-24 22:05:14 +00:00 |
|
Miroslav Stampar
|
52f910f752
|
added --beep (tested on Windows and Linux; for now turned off) switch
|
2010-10-23 09:38:46 +00:00 |
|
Miroslav Stampar
|
f1e2c1867f
|
Cosmetics
|
2010-10-22 21:13:12 +00:00 |
|
Miroslav Stampar
|
bc79eec702
|
removed queriesfile.py, implemented XMLObject approach (still shell.py and udf.py TODO)
|
2010-10-21 13:13:12 +00:00 |
|
Miroslav Stampar
|
5d3cbec457
|
no more regex. web server independent.
|
2010-10-20 09:35:46 +00:00 |
|
Miroslav Stampar
|
415524bd5a
|
remove --error, now it's only --error-test (it needs to return True to be able to use it)
|
2010-10-19 18:34:14 +00:00 |
|
Miroslav Stampar
|
4009ef385e
|
more update regarding error based injection support
|
2010-10-19 18:17:34 +00:00 |
|
Miroslav Stampar
|
4bc541ec3c
|
error based update
|
2010-10-19 14:47:13 +00:00 |
|
Miroslav Stampar
|
6a8b1046d4
|
first successfull run of error based sqlmap in history :). tested --banner, --current-user, --current-db on 4 major DBMSes. still hidden from users (turn on flag error in getValue() in inject.py)
|
2010-10-19 12:02:04 +00:00 |
|
Bernardo Damele
|
cd0fe8dde0
|
Updated sample configuration file and cmdline help
|
2010-10-17 00:07:53 +00:00 |
|
Bernardo Damele
|
64b9f94fcf
|
Renamed --common-prediction switch to --predict-output
|
2010-10-16 23:50:13 +00:00 |
|
Bernardo Damele
|
6211915da5
|
Cosmetic fix
|
2010-10-16 22:31:16 +00:00 |
|
Bernardo Damele
|
2129935e06
|
Split character for tamper scripts (--tamper option) is now comma, not semi-colon.
Minor enhancement
|
2010-10-16 21:52:16 +00:00 |
|
Miroslav Stampar
|
1336b97c2c
|
removed --useBetween switch and added new tampering module ./tamper/between.py
|
2010-10-15 23:48:07 +00:00 |
|
Miroslav Stampar
|
1ae4d0fc2a
|
added optimization group
|
2010-10-15 23:26:48 +00:00 |
|
Miroslav Stampar
|
c9f0c75030
|
removed --space (usage of tampering modules is now a prefered way to do it)
|
2010-10-15 12:52:33 +00:00 |
|
Bernardo Damele
|
c5e385f77a
|
More layout adjustments
|
2010-10-15 10:28:34 +00:00 |
|
Miroslav Stampar
|
4f7f20b94f
|
sorry, cosmetics
|
2010-10-14 23:18:29 +00:00 |
|
Miroslav Stampar
|
8b48833136
|
large commit with copyright header modifications
|
2010-10-14 14:41:14 +00:00 |
|
Miroslav Stampar
|
43a3ac2c3a
|
some bug fixes
|
2010-10-13 20:54:18 +00:00 |
|
Miroslav Stampar
|
34580f56fc
|
added --tamper option
|
2010-10-12 22:45:25 +00:00 |
|
Miroslav Stampar
|
d2ec132469
|
added --text-only switch
|
2010-10-12 19:41:29 +00:00 |
|
Miroslav Stampar
|
43892cddbb
|
some updates
|
2010-10-11 12:26:35 +00:00 |
|
Miroslav Stampar
|
8fcad29bbf
|
new feature --forms (still unfinished)
|
2010-10-10 18:56:43 +00:00 |
|
Miroslav Stampar
|
adf2231edb
|
minor update
|
2010-10-06 13:38:03 +00:00 |
|
Miroslav Stampar
|
56dbf0038f
|
minor update (for future implementation of more advanced error page logic)
|
2010-10-06 12:10:00 +00:00 |
|
Miroslav Stampar
|
cf8e92699c
|
changes regarding EXISTS feature
|
2010-09-30 12:35:45 +00:00 |
|
Miroslav Stampar
|
1da672e3c5
|
added default="False" to "store_true" parameters as it's a prefered way by http://docs.python.org/library/optparse.html
|
2010-09-27 13:23:29 +00:00 |
|
Miroslav Stampar
|
2e5f269650
|
update regarding --space option
|
2010-09-24 22:35:32 +00:00 |
|
Miroslav Stampar
|
9cd5d3bde7
|
added new option --space
|
2010-09-24 21:59:03 +00:00 |
|
Miroslav Stampar
|
abe1289016
|
minor update
|
2010-09-24 13:20:51 +00:00 |
|
Miroslav Stampar
|
48e0261e68
|
update for Feature #61
|
2010-09-24 13:19:35 +00:00 |
|
Miroslav Stampar
|
4fd7db52dd
|
minor update
|
2010-09-16 10:23:51 +00:00 |
|