| 
							
							
								 Bernardo Damele | d7d47b6257 | Minor bug fix (revert) | 2011-03-11 21:56:45 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e64f225e65 | minor refactoring | 2011-03-11 20:16:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2fd3f0d7b2 | minor update (added comment) | 2011-03-11 20:07:52 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6cc745f789 | removal of deprecated piece of code (replaced later with that getCurrentThreadData().disableStdOut) | 2011-03-11 20:04:15 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5eae525010 | this was bothering me for some time (POST and/or GET payloads needs to be urlencoded throughly) | 2011-03-11 19:57:44 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | d8a76ebe34 | Minor bug fix for counting of entries for error-based and partial UNION query SQL injection techs | 2011-03-11 16:03:19 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 3cb0ca4b63 | Minor bug fix for --privileges on PgSQL with error-based SQL inj technique | 2011-03-11 15:24:25 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 5af7410cb1 | Another bug fix for --privileges on PgSQL with UNION query technique | 2011-03-11 15:13:09 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 74ef1e53c7 | Minor bug fixes to --privileges for PostgreSQL query (corner case) | 2011-03-11 14:54:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1879a49506 | fix for a bug reported by andreoaz@gmail.com | 2011-03-10 20:40:12 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | eb1cda7065 | minor refactoring (more consistent) | 2011-03-09 12:06:32 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 62e3510387 | minor refactoring | 2011-03-09 11:37:37 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5c97f9a496 | improvement of url encoding technique (implemented failsafe routine for shortening too long GET queries) | 2011-03-09 09:36:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9b2962ff1c | now when we don't urlencode whole URI using : and \ as safe chars is not a good idea | 2011-03-09 08:56:29 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | eedd6a990d | removing space after , for our payloads | 2011-03-08 14:29:22 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3dc31f6273 | removing spaces after , in our queries | 2011-03-08 14:07:26 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 30619c599b | minor update regarding encoding (adding few safe chars for e.g. CHR(50)|...) | 2011-03-08 11:53:59 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 68c7247ee4 | bug fix (pgsql drop function requires input arguments - at cleanup() in plugins/generic/misc.py it's already fixed before) | 2011-03-08 10:46:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 99adbbeaa3 | los cosmeticados | 2011-03-07 22:04:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cc0306044c | adding SVN revision number support for non SVN client platforms | 2011-03-07 21:54:30 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8e7c3b4666 | update of THANKS file | 2011-03-07 21:29:06 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 154d947c62 | minor update | 2011-03-07 10:15:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 16b286982d | fix for a bug reported by nightman (AttributeError: 'list' object has no attribute 'split') | 2011-03-07 09:50:43 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 7524a0c0cf | Proper error message | 2011-03-04 11:59:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8edc3b3302 | further update regarding last commit | 2011-03-03 10:39:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | bc50387a17 | possible fix for a bug reported by Black Zero (UnicodeDecodeError for --forms) | 2011-03-03 09:42:50 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3a1f5744be | minor update to make counting variable totally independent of the urllib2's self.retried | 2011-03-02 10:42:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a010386a23 | finally a proper fix for that annoying recursive bug | 2011-03-02 10:29:38 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f27f05308a | minor update for masking sensitive data in error report (added aCred too) | 2011-03-02 10:09:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ad2e4002ea | minor improvement | 2011-03-01 10:38:27 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0f3cc153a3 | fix for --technique | 2011-03-01 09:54:06 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9856cb71de | redo of the last commit with comments added | 2011-02-28 18:58:05 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ade31b2cb0 | removal of obsolete item | 2011-02-28 18:49:25 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | da6a87af43 | update | 2011-02-28 16:59:39 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 50ba0fa955 | More adjustments | 2011-02-28 16:14:09 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 021fce5601 | Should be done with the ChangeLog - ready for 0.9. Minor adjustments to user's manual too. | 2011-02-28 15:23:05 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2bf212ffa9 | minor minor update | 2011-02-27 20:43:38 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7036190e8e | minor improvement of regular expression | 2011-02-27 17:58:01 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 21041f8b90 | further reflective value handling improvement | 2011-02-27 17:43:41 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | b47d3e1da3 | Huge update to user's manual. A lot to be done yet. | 2011-02-27 12:19:32 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 6e8ebd35f4 | Hide switch -x (XML output format) as it is incomplete and bugged and won't make it for 0.9 stable | 2011-02-27 12:17:41 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 60605b6e7c | Major bug fix to make --first and --last apply only to --dump's entries dump phase (in either of the blind SQL injection techs only) | 2011-02-27 12:14:13 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 88faedc0fe | fix for a bug reported by -insane- | 2011-02-26 17:48:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 11996ce12e | bug fix for international encoded letters | 2011-02-25 22:43:01 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 63b8156c00 | some update (if header key is non-unicode comformant) | 2011-02-25 09:43:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2bbbc9a41e | few updates | 2011-02-25 09:35:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | aa88361ab1 | incorporation of method for neutralization of reflective values | 2011-02-25 09:22:44 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 708ddf5608 | added protection mechanism against reflected values | 2011-02-24 16:52:46 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 38dc82e13e | If no Accept header field is present, then it is assumed that the client accepts all media types. | 2011-02-22 22:26:22 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 13f0d5ce00 | minor bug fix | 2011-02-22 14:51:42 +00:00 |  |