Commit Graph

  • 49bf34ffd9 minor fix Miroslav Stampar 2010-11-02 18:43:20 +0000
  • 861706fb31 fix for bug reported by ToR (unknown charset 'utf-8, text/html') Miroslav Stampar 2010-11-02 18:01:10 +0000
  • c7c84c3089 Closes #111 (DECLARE/CHAR encode xp_cmdshell parameter in MSSQL). Bernardo Damele 2010-11-02 15:31:51 +0000
  • 3596f81e6a Typo Bernardo Damele 2010-11-02 15:24:02 +0000
  • 70f6eab715 minor update Miroslav Stampar 2010-11-02 12:08:28 +0000
  • 685a8e7d2c refactoring of hard coded dbms names Miroslav Stampar 2010-11-02 11:59:24 +0000
  • 9d2c81baa9 more update for ms access Miroslav Stampar 2010-11-02 11:06:47 +0000
  • 6ad8bbfc8e one more ms access update Miroslav Stampar 2010-11-02 10:50:57 +0000
  • c98d8fed83 minor ms access update Miroslav Stampar 2010-11-02 10:13:36 +0000
  • 5269cb8c08 some code refactoring and beautification Miroslav Stampar 2010-11-02 09:06:38 +0000
  • 13e93f564a one bug fix in dynamic content engine and some code refactoring Miroslav Stampar 2010-11-02 07:32:08 +0000
  • 73b33ed765 fix for a bug reported by Ulisses Castro (Too many open files) - also, added an important caching mechanism with thread safe logic Miroslav Stampar 2010-11-01 20:56:13 +0000
  • 720e235d9a Fixed Windows 2003/2008 signatures. Added more old RedHat Server header signatures. Added old Debian etch signature too. Bernardo Damele 2010-10-31 18:18:49 +0000
  • e1319da4e8 Set Id property Bernardo Damele 2010-10-31 17:00:40 +0000
  • 486a113560 Consolidate logger messages for --*-test switches Bernardo Damele 2010-10-31 16:58:38 +0000
  • 46be570463 Proper HTTP version display Bernardo Damele 2010-10-31 15:41:28 +0000
  • f3cc41601c Added check on --first and --last values Bernardo Damele 2010-10-31 14:42:13 +0000
  • 0ffffef088 Implemented --tamper for direct connection too (-d) Bernardo Damele 2010-10-31 14:22:32 +0000
  • 27cea68bb8 No more need for 'place' parameter Bernardo Damele 2010-10-31 14:17:28 +0000
  • eab331ebd7 Minor bug fix Bernardo Damele 2010-10-31 13:46:08 +0000
  • 65a0a8d285 Delegate urlencoding to agent.py only Bernardo Damele 2010-10-31 13:28:05 +0000
  • 17e8abe841 Removed useless call to urlencode() Bernardo Damele 2010-10-31 12:47:22 +0000
  • c7b374534b Minor cosmetics Bernardo Damele 2010-10-31 12:29:00 +0000
  • 617edf7fc2 Minor bug fix Bernardo Damele 2010-10-31 12:24:19 +0000
  • fcada4df0f Removed debug print Bernardo Damele 2010-10-31 12:21:22 +0000
  • 2a2f949275 Minor bug fix Bernardo Damele 2010-10-31 12:20:38 +0000
  • 264247d318 revert of a stupid commit Bernardo Damele 2010-10-31 12:09:55 +0000
  • 2fb059a644 Bug fix Bernardo Damele 2010-10-31 12:02:20 +0000
  • 9d08cb3a6f Revert r2209 and minor code refactoring Bernardo Damele 2010-10-31 11:51:45 +0000
  • 3eda4510e2 Properly encode the cookie Bernardo Damele 2010-10-31 11:26:33 +0000
  • 79c3a5e527 Reverted to r2206 Bernardo Damele 2010-10-31 11:22:14 +0000
  • 3869ccebe8 Minor code refactoring Bernardo Damele 2010-10-31 11:17:51 +0000
  • 6afc9bffaa Minor bug fix: there will always be only one pair of delimiters as we add it for each place Bernardo Damele 2010-10-31 11:09:29 +0000
  • 3a48bee9b0 Minor code refactoring Bernardo Damele 2010-10-31 11:03:59 +0000
  • 5ba36f89df Fixed MySQL BETWEEN tamper script Bernardo Damele 2010-10-29 23:03:02 +0000
  • 8cf0ebde1e Cosmetics Bernardo Damele 2010-10-29 23:00:48 +0000
  • 0125198210 minor fix Miroslav Stampar 2010-10-29 21:19:28 +0000
  • cbf38436f2 minor update Miroslav Stampar 2010-10-29 16:15:23 +0000
  • 5a38ac7ea9 important update regarding (Bug #209) - probably more will be needed Miroslav Stampar 2010-10-29 16:11:50 +0000
  • a921fe0d5d fix for using --banner --stacked-test together Miroslav Stampar 2010-10-29 15:31:24 +0000
  • a0df231aa4 Avoid waiting 30 seconds when cleaning up the dbms and file system from sqlmap data Bernardo Damele 2010-10-29 13:09:53 +0000
  • 963fcb57b6 Minor bug fix Bernardo Damele 2010-10-29 12:36:37 +0000
  • f7d42af046 some fixes regarding --check-payload Miroslav Stampar 2010-10-29 11:00:23 +0000
  • b3b2c3864a Minor code refactoring Bernardo Damele 2010-10-29 10:51:09 +0000
  • 72a901347d Adjustments Bernardo Damele 2010-10-29 10:06:28 +0000
  • 53e735ea9d cosmetics Miroslav Stampar 2010-10-29 10:03:44 +0000
  • cc6efc4015 new extra added Miroslav Stampar 2010-10-29 09:59:18 +0000
  • 2b2634e92c As fcntl is only supported on Posix systems (no Windows) we need to check for the OS beforehand. Added proper check for impacket library too. Bernardo Damele 2010-10-29 09:50:41 +0000
  • d75578c81f some update regarding common tables Miroslav Stampar 2010-10-29 09:00:51 +0000
  • 895efd28a6 one more update regarding Bug #205 Miroslav Stampar 2010-10-28 23:22:13 +0000
  • 1f5224f1ac update Miroslav Stampar 2010-10-28 23:13:30 +0000
  • 788eb8fb50 update regarding Bug #205 Miroslav Stampar 2010-10-28 22:59:51 +0000
  • 762c2a1781 one more update for common tables Miroslav Stampar 2010-10-28 22:30:59 +0000
  • 4f8e9da1b6 Minor bug fix to properly delete sqlmap temporary files on the database server file system at shutdown. Minor improvements at ICMPsh tunnel to cleanup properly the dbms at shutdown and avoid checking/writing sys_bineval() UDF as it's a PE and needs to be called by sys_exec() only. Got rid of useless doubleslash param in delRemoteFile() method. Major code refactoring to xp_cmdshell.py methods and parent calls. Bernardo Damele 2010-10-28 00:19:40 +0000
  • 56c16cb471 Minor bug fixes and enhancements to ICMPsh tunnel Bernardo Damele 2010-10-27 23:01:17 +0000
  • 26cf6c2136 Adjusted impacket import check Bernardo Damele 2010-10-27 21:10:56 +0000
  • ed1f2da43f Updated Bernardo Damele 2010-10-27 21:05:58 +0000
  • a391be833b Implemented ICMP tunneling for out-of-band takeover (--os-pwn) as an alternative to TCP tunneling (Metasploit). It relies on icmpsh, the back-end dbms server has to be Windows as the icmpsh slave runs on Windows only for the moment. sqlmap needs to be executed as root to work. Bernardo Damele 2010-10-27 21:02:22 +0000
  • 1870e17e5d Written from scratch in Python the icmpsh master Bernardo Damele 2010-10-27 20:54:46 +0000
  • 43de8247ac Code refactoring Bernardo Damele 2010-10-27 20:39:50 +0000
  • 7715ba778b Updated Bernardo Damele 2010-10-27 14:41:03 +0000
  • 6075752c47 Added icmpsh from Nico Leidecker for future enhancement to --os-cmd and --os-pwn to make the user able to choose between TCP (Metasploit payloads) and ICMP (icmpsh software). Bernardo Damele 2010-10-27 14:36:45 +0000
  • d554ffc0ae yes, I am quite paranoid with cosmetics Bernardo Damele 2010-10-27 10:37:54 +0000
  • 0efecde248 Minor update to properly differentiate Windows 2003 by 2008 via HTTP response headers Bernardo Damele 2010-10-27 10:09:47 +0000
  • 1e5e4bbe34 update for common table names Miroslav Stampar 2010-10-27 09:15:18 +0000
  • 5cc1bd8a12 major fix for heuristic check Miroslav Stampar 2010-10-27 08:27:31 +0000
  • 749e25a217 Implementation of --passwords for Sybase Miroslav Stampar 2010-10-26 21:35:30 +0000
  • 1b90c1d131 added FreeBSD Miroslav Stampar 2010-10-26 20:48:52 +0000
  • 4da2046492 massive update of server fingerprints Miroslav Stampar 2010-10-26 20:00:29 +0000
  • 080c5aef80 minor update Miroslav Stampar 2010-10-26 19:08:11 +0000
  • 4d70f2c210 reverting back to 100 Miroslav Stampar 2010-10-26 15:42:54 +0000
  • 8211e6a2bd possible Miroslav Stampar 2010-10-26 11:29:09 +0000
  • 9b127e58d2 Adjusted for MySQL weirdness Bernardo Damele 2010-10-26 09:33:18 +0000
  • 8803096343 some update regarding beep() Miroslav Stampar 2010-10-26 08:32:58 +0000
  • b9ff91b6e9 update of beep Miroslav Stampar 2010-10-26 06:30:27 +0000
  • 9ec9d223e1 minor Miroslav Stampar 2010-10-26 06:08:40 +0000
  • 4ab3edfc94 Updated Bernardo Damele 2010-10-25 23:40:19 +0000
  • f5904d0bc0 Major bug fix to --union-test Bernardo Damele 2010-10-25 23:39:55 +0000
  • 7effd0c301 Cosmetics Bernardo Damele 2010-10-25 22:54:56 +0000
  • 8a9a57c709 update for Sybase and major bug fix for --passwords on MSSQL Miroslav Stampar 2010-10-25 22:11:38 +0000
  • 9b56fbafbe that Sybase is going to be pain in the ass Miroslav Stampar 2010-10-25 21:43:13 +0000
  • 73eea81b3a minor cosmetics Miroslav Stampar 2010-10-25 19:45:53 +0000
  • d7bf94d4d6 fix for --beep Miroslav Stampar 2010-10-25 19:16:42 +0000
  • 228ac0cde5 refactoring regarding --check-payload Miroslav Stampar 2010-10-25 18:38:54 +0000
  • 7c343c2d67 Forgot Bernardo Damele 2010-10-25 16:34:43 +0000
  • c7578d4ea1 update of THANKS Miroslav Stampar 2010-10-25 16:07:03 +0000
  • debaf2215f Consistency between cmdline.py, optiondict.py and sqlmap.conf and got rid of --union-use switch Bernardo Damele 2010-10-25 15:54:45 +0000
  • 378653a1ec added IDS payload testing Miroslav Stampar 2010-10-25 15:37:43 +0000
  • bdb9c37a7e Cosmetics Bernardo Damele 2010-10-25 15:17:59 +0000
  • 215175e3b7 Minor code adjustments Bernardo Damele 2010-10-25 14:11:47 +0000
  • 24c5d7b313 code refactoring Miroslav Stampar 2010-10-25 14:06:56 +0000
  • 9c94a233a1 conf.md5hash thrown out Miroslav Stampar 2010-10-25 13:52:21 +0000
  • 9a3879feba keeping things neat and tidy Miroslav Stampar 2010-10-25 12:33:49 +0000
  • 32728d14b7 fix for --union-use with --error-test Miroslav Stampar 2010-10-25 12:25:29 +0000
  • 71543092b7 update regarding comparison engine Miroslav Stampar 2010-10-25 12:00:59 +0000
  • 8df7c88174 implementation of a new dynamic content removal engine Miroslav Stampar 2010-10-25 10:41:37 +0000
  • db260c44d3 minor update Miroslav Stampar 2010-10-24 22:25:05 +0000
  • aa931efd4d several MySQL fixes/enhancements pointed out by Anton Mogilin Miroslav Stampar 2010-10-24 22:05:14 +0000
  • 52f910f752 added --beep (tested on Windows and Linux; for now turned off) switch Miroslav Stampar 2010-10-23 09:38:46 +0000
  • c5fb4edf3e update of THANKS Miroslav Stampar 2010-10-23 09:25:34 +0000