Commit Graph

  • 977988c0ab cosmetics Miroslav Stampar 2010-12-10 15:24:25 +0000
  • fa8d378e80 another update Miroslav Stampar 2010-12-10 15:18:15 +0000
  • 1ef44cfe60 fix Miroslav Stampar 2010-12-10 15:06:53 +0000
  • fe186cde55 proper fix Miroslav Stampar 2010-12-10 13:26:31 +0000
  • 9957881040 you won't believe commit Miroslav Stampar 2010-12-10 13:20:59 +0000
  • 7c87ad4065 Minor speedup in -f mysql Bernardo Damele 2010-12-10 13:05:46 +0000
  • b02bd55edc minor refactoring Miroslav Stampar 2010-12-10 13:04:36 +0000
  • 1fc9ed10a8 minor refactoring Miroslav Stampar 2010-12-10 12:30:36 +0000
  • 4d8628e8fb fix for booleans Miroslav Stampar 2010-12-10 12:26:01 +0000
  • fe2039f5ba coollyy little commits Miroslav Stampar 2010-12-10 11:32:46 +0000
  • d71e51e765 Minor improvement Bernardo Damele 2010-12-10 11:31:27 +0000
  • 4741874e9e Enhancement to speedup MySQL fingerprint Bernardo Damele 2010-12-10 11:27:36 +0000
  • e98b81fe32 another update Miroslav Stampar 2010-12-10 10:56:55 +0000
  • d5e7a8d305 update Miroslav Stampar 2010-12-10 10:54:17 +0000
  • b6dcbcef5b Minor fix Bernardo Damele 2010-12-10 10:52:55 +0000
  • 471d9ccd65 another fix of my lala Miroslav Stampar 2010-12-10 10:11:25 +0000
  • 029a6abba2 quick fix Miroslav Stampar 2010-12-10 09:54:25 +0000
  • 441fc8dbd9 update regarding boolean based expressions Miroslav Stampar 2010-12-09 21:15:18 +0000
  • d5fb921154 removed debug print Miroslav Stampar 2010-12-09 20:08:59 +0000
  • 1492823de0 it wasn't pretty, now it's pretty Miroslav Stampar 2010-12-09 20:06:20 +0000
  • bbffea2cbc bug fix Miroslav Stampar 2010-12-09 17:10:22 +0000
  • 0eb2c408a9 code refactoring Miroslav Stampar 2010-12-09 16:49:02 +0000
  • 7e2984b4b6 added stacked query support for Oracle Miroslav Stampar 2010-12-09 15:24:48 +0000
  • 4bb40c0a06 Higher the level for Oracle stacked tests just in case the SQL inj is within a PL/SQL function ('cause of no support for stacked queries by design on Oracle) Bernardo Damele 2010-12-09 15:14:18 +0000
  • d8edc5b244 adding stacked-query vector for Firebird Miroslav Stampar 2010-12-09 15:11:21 +0000
  • 13b522efc2 Added error-based support for MySQL < 5.0 - closes #14 Bernardo Damele 2010-12-09 15:09:03 +0000
  • 5aafd19957 added vector for SQLite's stacked query payload Miroslav Stampar 2010-12-09 15:06:40 +0000
  • df5f6bc1b7 Little precaution Bernardo Damele 2010-12-09 14:06:43 +0000
  • 9230877d98 cosmetics Bernardo Damele 2010-12-09 13:57:38 +0000
  • 5114c887ea minor minor update Miroslav Stampar 2010-12-09 13:51:44 +0000
  • 5fb04515d3 Added hidden (for the moment) switch --technique Bernardo Damele 2010-12-09 13:47:17 +0000
  • b80a86a669 that's it for common stuff today Miroslav Stampar 2010-12-09 12:59:22 +0000
  • b26e09fc71 another minor update Miroslav Stampar 2010-12-09 12:49:29 +0000
  • f712d2477e removed duplicate entries inside common wordlists (tables & columns) and added a script which does that automatically Miroslav Stampar 2010-12-09 12:41:16 +0000
  • c5b1f336ee another update Miroslav Stampar 2010-12-09 12:07:06 +0000
  • 06395b5408 update Miroslav Stampar 2010-12-09 12:03:10 +0000
  • cdff29ada7 update Miroslav Stampar 2010-12-09 11:23:44 +0000
  • 196131bbca minor cosmetics Miroslav Stampar 2010-12-09 10:42:00 +0000
  • 71761ba9a5 another fix for another beautiful heavy query payload which took a few 100 megs and 5 mins to run Miroslav Stampar 2010-12-09 10:35:18 +0000
  • 094baadc5b bug fix (in SELECT based heavy queries COUNT(*) should be used; otherwise multiple row error happens without proper delay) Miroslav Stampar 2010-12-09 10:17:04 +0000
  • ec5c08ca7a cosmetics Miroslav Stampar 2010-12-09 09:24:20 +0000
  • 3fd1c37d53 update Miroslav Stampar 2010-12-09 07:49:18 +0000
  • db39dc32fc minor update Miroslav Stampar 2010-12-09 00:59:39 +0000
  • 0c01be0eeb Ugly work-around to avoid unescaping WAITFOR DELAY time between single quotes (unescaped CHAR(..) value does not work). Bernardo Damele 2010-12-09 00:34:02 +0000
  • 9c61adb21d Cosmetics Bernardo Damele 2010-12-09 00:26:06 +0000
  • b5c6527c72 Minor fix Bernardo Damele 2010-12-09 00:25:48 +0000
  • 3b293c4ea7 Added possible stacked queries time-based blind vector for MSSQL Bernardo Damele 2010-12-08 23:55:42 +0000
  • f5ce739bdf Added support for time-based blind SQL injection via stacked queries too. Need to add vectors for some DBMS yet. Bernardo Damele 2010-12-08 23:52:31 +0000
  • 10ef2b5de8 Minor bug fix Bernardo Damele 2010-12-08 23:09:42 +0000
  • 54f6673609 update Miroslav Stampar 2010-12-08 22:38:26 +0000
  • d6077273e0 update Miroslav Stampar 2010-12-08 22:14:42 +0000
  • 5aee1fd8e0 updated THANKS file Miroslav Stampar 2010-12-08 21:19:46 +0000
  • 258e9fb50e fix for a "bug" reported by Spencer J. McIntyre (os.makedirs(conf.outputPath, 0755) -> permission denied) Miroslav Stampar 2010-12-08 21:16:18 +0000
  • 69c4f94980 update Miroslav Stampar 2010-12-08 15:40:01 +0000
  • 81c16926c1 code refactoring some more Miroslav Stampar 2010-12-08 14:46:07 +0000
  • 40fadf2f35 minor update Miroslav Stampar 2010-12-08 14:33:10 +0000
  • 95b48746a6 cosmetics Miroslav Stampar 2010-12-08 14:29:09 +0000
  • ed09c53ee4 minor minor update Miroslav Stampar 2010-12-08 14:27:37 +0000
  • 01cf1394a4 code refactoring Miroslav Stampar 2010-12-08 14:26:40 +0000
  • af22679605 minor update Miroslav Stampar 2010-12-08 13:09:27 +0000
  • 6223f25dd9 code beautification Miroslav Stampar 2010-12-08 13:04:48 +0000
  • 64cc2588f1 now resume is available for time-based blinds too Miroslav Stampar 2010-12-08 12:49:26 +0000
  • 537b619165 removing junk Miroslav Stampar 2010-12-08 12:30:25 +0000
  • b5e45939e3 sqlmap premiere of blind time based query/bisection Miroslav Stampar 2010-12-08 12:28:54 +0000
  • ad00fe13c1 another fix for MySQL time based payloads Miroslav Stampar 2010-12-08 12:00:27 +0000
  • 8227e6d3cf bug fix for BENCHMARK time-based vectors Miroslav Stampar 2010-12-08 11:49:55 +0000
  • 47bb31fb47 code refactoring Miroslav Stampar 2010-12-08 11:30:25 +0000
  • 1ae2fa7f1a update regarding time based payloads Miroslav Stampar 2010-12-08 11:26:54 +0000
  • bdff4aba6a switching to quick_ratio Miroslav Stampar 2010-12-07 23:57:43 +0000
  • c1b82cf09c ratio() gives a considerable lag on real life cases, as real_quick_ratio() gives almost as good results Miroslav Stampar 2010-12-07 23:53:44 +0000
  • a4a63f5b1e minor update Miroslav Stampar 2010-12-07 23:49:00 +0000
  • 293ce18fed two major bug fixes regarding time calculation (previously comparison was also a part of "delta", which screwed results in cases with large pages; other was a standard distribution based one) Miroslav Stampar 2010-12-07 23:32:33 +0000
  • b21eb88905 minor update Miroslav Stampar 2010-12-07 22:45:38 +0000
  • 575e50673b minor update Miroslav Stampar 2010-12-07 19:27:01 +0000
  • 398b82644a little explanation Miroslav Stampar 2010-12-07 19:25:26 +0000
  • dc651d59ec little mathematics here and there (used "Rules for normally distributed data") Miroslav Stampar 2010-12-07 19:19:12 +0000
  • ee72838231 Removed debug print Bernardo Damele 2010-12-07 17:19:29 +0000
  • 5f97312f29 Minor fix Bernardo Damele 2010-12-07 17:17:38 +0000
  • 8ff7c9a5a1 Works on Oracle's GROUP BY too Bernardo Damele 2010-12-07 17:17:01 +0000
  • 81e7465ed2 Cosmetics Bernardo Damele 2010-12-07 17:16:21 +0000
  • ecd4a5a532 added standard deviation check in time based tests Miroslav Stampar 2010-12-07 16:39:31 +0000
  • 294119d2ec more advanced time technique(s) Miroslav Stampar 2010-12-07 16:04:53 +0000
  • 4959da3ce6 it's a must to double check time based payloads Miroslav Stampar 2010-12-07 14:59:11 +0000
  • e53fef546e update regarding session page templates Miroslav Stampar 2010-12-07 14:35:31 +0000
  • add6235b16 removed pageTemplate from injection(s), it's not longer stored in session, and it's reloaded when resuming from session Miroslav Stampar 2010-12-07 14:06:54 +0000
  • 0dc630203f code refactoring Miroslav Stampar 2010-12-07 13:34:06 +0000
  • 4f01d4c109 number crunching based time payloads are now affected by conf.timeSec Miroslav Stampar 2010-12-07 13:24:18 +0000
  • d0936bc8ed adding vectors for SQLite time-based payloads Miroslav Stampar 2010-12-07 13:14:56 +0000
  • 54b8cb76a1 Messed up with my last merge, all fixed now Bernardo Damele 2010-12-07 12:59:53 +0000
  • b38a634d95 bug fix Miroslav Stampar 2010-12-07 12:55:31 +0000
  • 7c32db6e9d Forgot when merged with my last commit Bernardo Damele 2010-12-07 12:52:09 +0000
  • acac0d346f Minor bug fixes and adjustments Bernardo Damele 2010-12-07 12:45:45 +0000
  • 8e78057ac8 Added counter of total HTTP(s) requests done during detection phase Bernardo Damele 2010-12-07 12:33:47 +0000
  • effd2ca0e3 Cosmetics Bernardo Damele 2010-12-07 12:32:58 +0000
  • 2b2b7dc3a6 added vectors for time-based Firebird payloads Miroslav Stampar 2010-12-07 12:20:48 +0000
  • 36a7fca8d5 added time-based payload vector for MSSQL Miroslav Stampar 2010-12-07 12:06:25 +0000
  • 485981c619 added vectors for PostgresSQL time-based payloads Miroslav Stampar 2010-12-07 11:57:33 +0000
  • f9085e01e7 added vectors for Oracle time-based payloads Miroslav Stampar 2010-12-07 11:47:29 +0000
  • 2af8835a94 fix for a bug reported by ToR (origValue = paramDict[kb.injection.parameter] -> KeyError in resume with missing injection parameter) Miroslav Stampar 2010-12-07 10:57:32 +0000
  • 3d87489de5 minor update Miroslav Stampar 2010-12-07 08:05:03 +0000