Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							db39dc32fc
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2010-12-09 00:59:39 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							0c01be0eeb
							
						
					 | 
					
						
						
							
							Ugly work-around to avoid unescaping WAITFOR DELAY time between single quotes (unescaped CHAR(..) value does not work).
						
						
						
						
						
					 | 
					
						2010-12-09 00:34:02 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							9c61adb21d
							
						
					 | 
					
						
						
							
							Cosmetics
						
						
						
						
						
					 | 
					
						2010-12-09 00:26:06 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							b5c6527c72
							
						
					 | 
					
						
						
							
							Minor fix
						
						
						
						
						
					 | 
					
						2010-12-09 00:25:48 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							f5ce739bdf
							
						
					 | 
					
						
						
							
							Added support for time-based blind SQL injection via stacked queries too. Need to add vectors for some DBMS yet.
						
						
						
						
						
					 | 
					
						2010-12-08 23:52:31 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							10ef2b5de8
							
						
					 | 
					
						
						
							
							Minor bug fix
						
						
						
						
						
					 | 
					
						2010-12-08 23:09:42 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							54f6673609
							
						
					 | 
					
						
						
							
							update
						
						
						
						
						
					 | 
					
						2010-12-08 22:38:26 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							d6077273e0
							
						
					 | 
					
						
						
							
							update
						
						
						
						
						
					 | 
					
						2010-12-08 22:14:42 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							258e9fb50e
							
						
					 | 
					
						
						
							
							fix for a "bug" reported by Spencer J. McIntyre (os.makedirs(conf.outputPath, 0755) -> permission denied)
						
						
						
						
						
					 | 
					
						2010-12-08 21:16:18 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							81c16926c1
							
						
					 | 
					
						
						
							
							code refactoring some more
						
						
						
						
						
					 | 
					
						2010-12-08 14:46:07 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							40fadf2f35
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2010-12-08 14:33:10 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							95b48746a6
							
						
					 | 
					
						
						
							
							cosmetics
						
						
						
						
						
					 | 
					
						2010-12-08 14:29:09 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							ed09c53ee4
							
						
					 | 
					
						
						
							
							minor minor update
						
						
						
						
						
					 | 
					
						2010-12-08 14:27:37 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							01cf1394a4
							
						
					 | 
					
						
						
							
							code refactoring
						
						
						
						
						
					 | 
					
						2010-12-08 14:26:40 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							af22679605
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2010-12-08 13:09:27 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							6223f25dd9
							
						
					 | 
					
						
						
							
							code beautification
						
						
						
						
						
					 | 
					
						2010-12-08 13:04:48 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							64cc2588f1
							
						
					 | 
					
						
						
							
							now resume is available for time-based blinds too
						
						
						
						
						
					 | 
					
						2010-12-08 12:49:26 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							537b619165
							
						
					 | 
					
						
						
							
							removing junk
						
						
						
						
						
					 | 
					
						2010-12-08 12:30:25 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							b5e45939e3
							
						
					 | 
					
						
						
							
							sqlmap premiere of blind time based query/bisection
						
						
						
						
						
					 | 
					
						2010-12-08 12:28:54 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							47bb31fb47
							
						
					 | 
					
						
						
							
							code refactoring
						
						
						
						
						
					 | 
					
						2010-12-08 11:30:25 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							1ae2fa7f1a
							
						
					 | 
					
						
						
							
							update regarding time based payloads
						
						
						
						
						
					 | 
					
						2010-12-08 11:26:54 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							bdff4aba6a
							
						
					 | 
					
						
						
							
							switching to quick_ratio
						
						
						
						
						
					 | 
					
						2010-12-07 23:57:43 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							c1b82cf09c
							
						
					 | 
					
						
						
							
							ratio() gives a considerable lag on real life cases, as real_quick_ratio() gives almost as good results
						
						
						
						
						
					 | 
					
						2010-12-07 23:53:44 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							a4a63f5b1e
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2010-12-07 23:49:00 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							293ce18fed
							
						
					 | 
					
						
						
							
							two major bug fixes regarding time calculation (previously comparison was also a part of "delta", which screwed results in cases with large pages; other was a standard distribution based one)
						
						
						
						
						
					 | 
					
						2010-12-07 23:32:33 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							b21eb88905
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2010-12-07 22:45:38 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							575e50673b
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2010-12-07 19:27:01 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							398b82644a
							
						
					 | 
					
						
						
							
							little explanation
						
						
						
						
						
					 | 
					
						2010-12-07 19:25:26 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							dc651d59ec
							
						
					 | 
					
						
						
							
							little mathematics here and there (used "Rules for normally distributed data")
						
						
						
						
						
					 | 
					
						2010-12-07 19:19:12 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							ee72838231
							
						
					 | 
					
						
						
							
							Removed debug print
						
						
						
						
						
					 | 
					
						2010-12-07 17:19:29 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							5f97312f29
							
						
					 | 
					
						
						
							
							Minor fix
						
						
						
						
						
					 | 
					
						2010-12-07 17:17:38 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							81e7465ed2
							
						
					 | 
					
						
						
							
							Cosmetics
						
						
						
						
						
					 | 
					
						2010-12-07 17:16:21 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							ecd4a5a532
							
						
					 | 
					
						
						
							
							added standard deviation check in time based tests
						
						
						
						
						
					 | 
					
						2010-12-07 16:39:31 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							294119d2ec
							
						
					 | 
					
						
						
							
							more advanced time technique(s)
						
						
						
						
						
					 | 
					
						2010-12-07 16:04:53 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							4959da3ce6
							
						
					 | 
					
						
						
							
							it's a must to double check time based payloads
						
						
						
						
						
					 | 
					
						2010-12-07 14:59:11 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							e53fef546e
							
						
					 | 
					
						
						
							
							update regarding session page templates
						
						
						
						
						
					 | 
					
						2010-12-07 14:35:31 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							add6235b16
							
						
					 | 
					
						
						
							
							removed pageTemplate from injection(s), it's not longer stored in session, and it's reloaded when resuming from session
						
						
						
						
						
					 | 
					
						2010-12-07 14:06:54 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							0dc630203f
							
						
					 | 
					
						
						
							
							code refactoring
						
						
						
						
						
					 | 
					
						2010-12-07 13:34:06 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							8e78057ac8
							
						
					 | 
					
						
						
							
							Added counter of total HTTP(s) requests done during detection phase
						
						
						
						
						
					 | 
					
						2010-12-07 12:33:47 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							effd2ca0e3
							
						
					 | 
					
						
						
							
							Cosmetics
						
						
						
						
						
					 | 
					
						2010-12-07 12:32:58 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							2af8835a94
							
						
					 | 
					
						
						
							
							fix for a bug reported by ToR (origValue = paramDict[kb.injection.parameter] -> KeyError in resume with missing injection parameter)
						
						
						
						
						
					 | 
					
						2010-12-07 10:57:32 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							3d87489de5
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2010-12-07 08:05:03 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							0da1ebde7d
							
						
					 | 
					
						
						
							
							introducing PostgreSQL time based blind
						
						
						
						
						
					 | 
					
						2010-12-07 00:51:14 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							61f82fd274
							
						
					 | 
					
						
						
							
							introducing [DELAYED] for heavy query time based payloads when response time is non-deterministic
						
						
						
						
						
					 | 
					
						2010-12-07 00:27:26 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							2735848ab6
							
						
					 | 
					
						
						
							
							removed ERROR_SPACE
						
						
						
						
						
					 | 
					
						2010-12-06 22:40:07 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							9ccc8f90a3
							
						
					 | 
					
						
						
							
							minor cosmetic update ("heuristics shows" is not grammatically correct)
						
						
						
						
						
					 | 
					
						2010-12-06 18:47:22 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							d336f1df23
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2010-12-06 18:44:42 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							d77ddbee47
							
						
					 | 
					
						
						
							
							OR based inference works for the first time in history and fingerprint of 4 major DBMSes is now injection based (instead of AND)
						
						
						
						
						
					 | 
					
						2010-12-06 18:20:57 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							27ee9a5ccf
							
						
					 | 
					
						
						
							
							minor refactoring
						
						
						
						
						
					 | 
					
						2010-12-06 15:50:19 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							e8be14e00a
							
						
					 | 
					
						
						
							
							minor refactoring
						
						
						
						
						
					 | 
					
						2010-12-06 07:48:14 +00:00 | 
					
					
						
						
							
							
							
						
					 |