| 
							
							
								 Miroslav Stampar | 017ea9e686 | update | 2010-12-23 14:06:22 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 73f33c1999 | bug fix of re-introduced bug (in multiple target mode sites with similar URI weren't skipped) | 2010-12-23 11:28:13 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8fc60215ed | lol. this was a pesky bug. heuristic wasn't working on one mssql test site and i couldn't find why. at end the problem was that when the HTTP code was raised (like 500) no parseResponse was called. | 2010-12-22 19:12:46 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7c06dbffc3 | bug fix (AttributeError: 'unicode' object has no attribute 'sort') | 2010-12-22 18:55:50 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | c1f2534e9a | More bug fixes to properly distinguish between full inband and single-entry inband sql injections | 2010-12-22 15:47:52 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 250608660d | Minor bug fix to always show HTTP request and response when verbose is set accordingly to 4, 5 or 6 regardless of the HTTP response code (error or not) | 2010-12-22 13:41:36 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 5228f336da | Minor fix for ctrl+c during detection phase | 2010-12-22 13:15:44 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 08c88495d0 | removed that ugly hack | 2010-12-22 13:09:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8212b7b745 | bug fix | 2010-12-22 12:16:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5be9c04e44 | update regarding Sybase syntax | 2010-12-22 10:39:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d974a966b8 | minor fix for end phase (Ctrl+C) | 2010-12-21 23:55:55 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | fb75d0636b | minor update | 2010-12-21 23:42:59 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 39a13077c4 | minor bug fix | 2010-12-21 23:09:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 09479c85dc | minor bug fix | 2010-12-21 22:35:44 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7a525f28d4 | cosmetics | 2010-12-21 15:26:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b2e7f9484d | minor tuning (2 techniques MAX per value used) | 2010-12-21 15:24:14 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6c1133c4d4 | some code refactoring | 2010-12-21 15:13:13 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 466d61ee85 | minor fix | 2010-12-21 14:29:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 385e208f38 | code refactoring regarding standard output suppression and some threading issues | 2010-12-21 14:21:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0e68248f60 | minor update of heuristic check | 2010-12-21 12:56:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 16f1f4e13e | when doing dynamic checks there are cases when 404 can be raised (perfectly normal) | 2010-12-21 11:04:49 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | aca074b769 | Removed unused outdated code | 2010-12-21 10:49:52 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | ad6b528b33 | Bit more verbose comment | 2010-12-21 10:47:39 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6b37ddada4 | removed some blank trailing spaces (with extra/shutils/blanks.sh) | 2010-12-21 10:31:56 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 1a3f57e5fe | Cosmetics | 2010-12-21 09:23:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d554460aec | minor fix | 2010-12-21 01:09:39 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 116c141dfa | another fix | 2010-12-21 00:47:07 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 416755c0b7 | minor adjustments | 2010-12-21 00:25:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8067365b93 | fix for a bug reported by m4l1c3 (AttributeError: '_MainThread' object has no attribute 'ident') | 2010-12-20 23:47:53 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e10670d9ac | added end detection phase choice into Ctrl+C list | 2010-12-20 23:34:00 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 29001a4fce | minor update | 2010-12-20 23:21:01 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b34fe5c334 | no more need for such a huge timeout because any timeout exceptions will now be considered as a successful time-based attack (previously we wanted to get back to the program, hence there was such a huge timeout) | 2010-12-20 22:49:48 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8fd3e7ba1f | thread based data added | 2010-12-20 22:45:01 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c9e8aae8a2 | we'll need to do some cleanup around threading data model we use (some of the data we currently use we'll need to spread via copies around used threads) | 2010-12-20 19:34:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e09bc2406c | minor refactoring | 2010-12-20 19:24:20 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5852bad963 | some refactoring | 2010-12-20 18:56:06 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 19d8733e9a | this is strictly for educational purposes | 2010-12-20 17:30:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c948bced61 | should solve the problem with timeout problems in time-based payloads | 2010-12-20 16:45:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | eaf8929085 | more minor updates | 2010-12-20 10:48:53 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | fd00ff7a82 | minor bug fix | 2010-12-20 10:37:03 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e9f1ecb9e7 | minor update | 2010-12-20 10:32:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 10a7a2dfb2 | kids, don't use this at home | 2010-12-20 10:13:14 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 13d5b2c0ff | code refactoring | 2010-12-20 09:44:21 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 4cb83654dc | minor update | 2010-12-18 16:28:21 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 36862e2efa | update | 2010-12-18 15:57:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 21d083272e | minor minor fix | 2010-12-18 14:31:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 4f73feec2f | now dictionary attack on multiple hash formats is supported (like mysql_passwd and mysql_old_passwd in one database) | 2010-12-18 14:11:49 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 05c6d661e8 | cosmetics | 2010-12-18 10:49:49 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 03220d34ba | added Ctrl+C check in detection phase | 2010-12-18 10:42:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e355f92f22 | bug fix | 2010-12-18 10:02:01 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | fe67d3827c | code refactoring and some fixes | 2010-12-18 09:51:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 108a96c6b4 | some fixes | 2010-12-17 21:45:20 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a19cb2c13a | code refactoring (added UNKNOWN_DBMS_VERSION instead of "Unknown") | 2010-12-17 21:29:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b4450c6ddd | added one more level of MSSQL version check (if first fails for some reason) | 2010-12-17 21:01:14 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 07609bfb53 | minor fix | 2010-12-17 19:33:20 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 323af45ce4 | added one more time request payload to confirm test results | 2010-12-17 07:53:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e3fa3b0e8e | fix for a minor bug reported by nightman (AttributeError: 'NoneType' object has no attribute 'getFingerprint') | 2010-12-17 07:48:32 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 95b2c0803b | minor fix | 2010-12-15 20:51:29 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | de54219571 | code refactoring | 2010-12-15 12:50:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cda00c7501 | code refactoring | 2010-12-15 12:43:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3f34b06a24 | minor cosmetics | 2010-12-15 12:34:14 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 445cc3bf3c | minor cosmetics | 2010-12-15 12:15:43 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c1c525aaea | quick fix of a fix | 2010-12-15 12:10:33 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7cfeb5447b | minor update | 2010-12-15 11:46:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 4dec24d056 | quick fix for a bug reported by Andreas Constantinides (KeyError: 5) | 2010-12-15 11:30:29 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f8a01ddaf8 | minor update | 2010-12-15 11:21:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 63f5c35c23 | bug fix | 2010-12-15 10:02:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c3d0295d21 | minor update (checking for --time-sec value) | 2010-12-14 12:37:21 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b75d7fa348 | minor cache based optimization | 2010-12-14 12:22:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 270ae0f080 | just in case as maybe there will be some boolean expression to check where we won't expect None, but explicitly True/False | 2010-12-14 09:05:00 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 04caef6de0 | Tuning | 2010-12-13 23:04:26 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | cfcee6439e | Cosmetics | 2010-12-13 21:55:30 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 86690682c7 | Minor bug fix to respect -v value in --common-tables and --common-columns | 2010-12-13 21:37:12 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 4b79227b5a | Minor bug fix to properly merge options from .conf file (-c) with command line switches | 2010-12-13 21:36:23 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | db844c1785 | No point in showing the error-based inject payload, it's same as the one showed in -v3 | 2010-12-13 21:35:20 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 698f30e65e | Cosmetics | 2010-12-13 21:34:35 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | a02dd6b55b | Minor enhancement to speedup active dbms fingerprint (-f). Code cleanup and refactoring. | 2010-12-13 21:33:42 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d56f47d530 | fix for a bug reported by black zero (ValueError: invalid literal for int() with base 10: '1-20') | 2010-12-12 23:59:55 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6a3c4485e6 | minor update (removing extra ()) | 2010-12-12 14:44:39 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e98d9c08e1 | dumping table is now possible on Firebird too | 2010-12-12 14:38:07 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c93634b6c7 | blind dumping of tables in sqlite implemented | 2010-12-11 22:13:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b1babeefe5 | update regarding dumping of tables with blind on Sqlite | 2010-12-11 22:00:16 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f7344a5fc3 | update | 2010-12-11 21:28:11 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6a24048aa6 | urllib2 doesn't play well with '\n' when non unescaped chars used | 2010-12-11 21:17:54 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e6c66fa37c | update regarding expectingNone in fingerprinting mode to cancel drop down to other techniques available | 2010-12-11 17:55:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e32fa9df43 | further update regarding bugtrace's report | 2010-12-11 17:32:15 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5d18c98ec2 | quick fix for a bug reported by bugtrace (not using __goBooleanProxy because we don't have a proper vector this moment) | 2010-12-11 17:20:39 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 03447acc1d | avoiding some trashy match ratios | 2010-12-11 17:12:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d2a3e8f44f | first time firebird error-based query success | 2010-12-11 11:17:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f021548bd0 | added inference failsafe (like in for instance Firebirds SUBSTR always returns a string value, no matter which starting index you use) | 2010-12-11 10:52:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c17f444aab | minor fix | 2010-12-11 10:22:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3dc0a51d34 | major bug fix with boolean expressions | 2010-12-11 08:46:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ac9080c07b | update | 2010-12-11 08:24:29 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 66db80804d | fix | 2010-12-10 16:03:32 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 435f48b8cc | polite cosmetics | 2010-12-10 15:28:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 977988c0ab | cosmetics | 2010-12-10 15:24:25 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | fa8d378e80 | another update | 2010-12-10 15:18:15 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1ef44cfe60 | fix | 2010-12-10 15:06:53 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | fe186cde55 | proper fix | 2010-12-10 13:26:31 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9957881040 | you won't believe commit | 2010-12-10 13:20:59 +00:00 |  |