| 
							
							
								 Bernardo Damele | 3822b494ea | Major bug fix to properly deal with EXISTS() when forging query or retrieving the query columns. | 2011-01-17 23:43:37 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 35fb50a6ee | Major bug fix | 2011-01-17 22:56:04 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 47565f9459 | Minor code refactoring | 2011-01-17 21:13:59 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 041abb56e2 | you can't believe how much man can learn when having good testing points | 2011-01-17 13:59:22 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d225c5c9aa | was wrong about this one (just now tested on a real site) | 2011-01-17 11:00:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ac0b5e6dbc | proper way to handle this (console output has totally different encoding than the page one) | 2011-01-17 10:27:36 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 34d13be0d3 | minor update regarding default page encoding | 2011-01-17 10:23:37 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5c857779c1 | important fix for unicode based character inference | 2011-01-17 10:15:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0fcca671bd | information update regarding common password suffixes | 2011-01-17 09:28:25 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a835f233ac | fix for a bug reported by buawig@gmail.com (AttributeError: 'module' object has no attribute 'set_completer') | 2011-01-17 00:17:31 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2041361695 | minor cosmetics | 2011-01-16 23:20:52 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e2c821eb81 | minor cosmetics | 2011-01-16 22:35:54 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e881465a9f | minor improvement | 2011-01-16 20:55:07 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a6516798c0 | proper fix for that previous "stacked" fix (that one screwed other injection types) | 2011-01-16 19:25:10 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5476a8a27e | russian sites are great for testing :) | 2011-01-16 19:00:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 19dcaeaabf | fix for "Payload: id=1 ; SELECT PG_SLEEP(5);--" (blank space was added in case when prefixes weren't stated) | 2011-01-16 18:25:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 30d6791968 | update regarding time based data retrieval | 2011-01-16 17:52:42 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2001bad7e1 | automatic adjustment of timeSec for delayed queries | 2011-01-16 12:04:32 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 71391874eb | slightly faster and thread safer inference | 2011-01-16 10:52:42 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 0fc4ebdc1b | Major bug fix. Minor code refactoring. | 2011-01-16 01:17:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 29ea0950b6 | now False is also affected (along with None and "") | 2011-01-15 23:43:26 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 558f3894f4 | Minor improvement | 2011-01-15 23:20:52 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | d3a28124b1 | More code cleanup | 2011-01-15 23:11:36 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3873d204bb | important update for dictionary attack | 2011-01-15 15:56:11 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e17ac5fdca | update | 2011-01-15 15:14:22 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5bdb50c224 | code review part 3 | 2011-01-15 13:15:10 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1fa8f0cba7 | code reviewing part 2 | 2011-01-15 12:53:40 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6a0e0cde3c | code review of modules in lib/core directory | 2011-01-15 12:13:45 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | daf5662eab | update | 2011-01-14 15:33:49 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 1cfd6a6b9d | Code cleanup | 2011-01-14 15:16:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 08f7e20c51 | minor code refactoring | 2011-01-14 14:55:59 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | fb9d7cdfaa | refactoring, code clearing and removal of obsolete switch --longest-common | 2011-01-14 14:37:03 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 534f51f9fc | Minor bug fix | 2011-01-14 14:20:28 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 3c95d71ea5 | Minor bug fix - restored of so called kb.misc.testedDbms (now kb.misc.fpDbms) to force the DBMS (only) during the fingerprint phase | 2011-01-14 11:55:20 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 7d9fd5a7b7 | Minor bug fix | 2011-01-14 09:49:14 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 676b95b30a | minor code refactoring | 2011-01-14 09:44:56 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | f8c04ce020 | Minor bug fix | 2011-01-13 20:59:13 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 2ac8debea0 | Major code refactoring - moved to one location only (getIdentifiedDBMS() in common.py) the retrieval of identified/fingerprinted DBMS. Minor bug fixes thanks to previous refactoring too. | 2011-01-13 17:36:54 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b0fdbdb13b | minor update | 2011-01-13 15:15:56 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 877ea31521 | Verbose docstring | 2011-01-13 12:05:14 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ac5b49f555 | update | 2011-01-13 11:24:03 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | af4ee81e62 | Cosmetics | 2011-01-13 11:23:07 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ece2eb31ca | minor update | 2011-01-13 11:08:29 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | ca33728fbc | Minor fix to avoid query splitting/unpacking when the statement is EXISTS() | 2011-01-13 10:00:40 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | be6e2d6a31 | Important bug fix. Minor code restyling. | 2011-01-13 09:41:55 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | b3a0f38f3f | Minor code refactoring and added internal debug prints | 2011-01-12 12:03:23 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | af9725214a | Properly deal with partial (single entry) UNION injections. Got rid of kb.union*, now it's all stored/used from kb.injection.
Minor bug fix with where=2 detection phase. | 2011-01-12 12:01:32 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 3cff42986f | Code cleanup | 2011-01-12 01:17:04 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 8a67aea754 | One more step to fully working UNION exploitation after merge into detection phase | 2011-01-12 01:13:32 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | b5c6f7556f | Minor update | 2011-01-12 00:53:48 +00:00 |  |