Commit Graph

  • 68d39d5976 minor minor fix Miroslav Stampar 2010-10-23 09:12:08 +0000
  • 32a4350779 update for MaxDB Miroslav Stampar 2010-10-23 09:03:59 +0000
  • 98f5586b87 minor update Miroslav Stampar 2010-10-23 08:05:24 +0000
  • f8850e3f41 update (xml fix and refactoring) Miroslav Stampar 2010-10-23 07:44:34 +0000
  • a7a53af924 update for Sybase Miroslav Stampar 2010-10-23 07:37:43 +0000
  • a8e42a4f2b bug fix Miroslav Stampar 2010-10-23 06:42:21 +0000
  • f1e2c1867f Cosmetics Miroslav Stampar 2010-10-22 21:13:12 +0000
  • 2194d47782 setting conf.threads when -o switch is used Miroslav Stampar 2010-10-22 19:10:45 +0000
  • e4089e86e8 new tamper script (reference: http://hakipedia.com/index.php/SQL_Injection) Miroslav Stampar 2010-10-22 18:57:04 +0000
  • e6e48c5556 fix for Bug #204 Miroslav Stampar 2010-10-22 18:23:46 +0000
  • 1288def3b7 Cosmetics Bernardo Damele 2010-10-22 14:23:14 +0000
  • dec4d858b3 fix for Bug #207 Miroslav Stampar 2010-10-22 14:01:48 +0000
  • 1b2ec826bf misc fixes regarding new query retrieval format Miroslav Stampar 2010-10-21 23:17:06 +0000
  • a9b50a1e82 minor fix Miroslav Stampar 2010-10-21 23:09:57 +0000
  • 2de3081b50 minor update Miroslav Stampar 2010-10-21 23:03:42 +0000
  • 24e4429bf6 or better yet, there is no need for _ or *args on getPrivileges (tried with SQLite and MSSql which crashed) Miroslav Stampar 2010-10-21 13:31:06 +0000
  • fe3967bdec fix for --privileges (on MSSql --privileges returned exception) Miroslav Stampar 2010-10-21 13:28:29 +0000
  • bc79eec702 removed queriesfile.py, implemented XMLObject approach (still shell.py and udf.py TODO) Miroslav Stampar 2010-10-21 13:13:12 +0000
  • be443c6947 refactoring regarding __START__,... Miroslav Stampar 2010-10-21 09:51:07 +0000
  • 2668c95ef4 added default HTTP version used by httplib and urllib2 Miroslav Stampar 2010-10-21 09:10:07 +0000
  • 7f1aa3b94f Removed unused imports Bernardo Damele 2010-10-20 22:48:51 +0000
  • c60edf7c17 Minor cosmetics Bernardo Damele 2010-10-20 22:43:02 +0000
  • 526694c80c Minor fix Bernardo Damele 2010-10-20 22:24:06 +0000
  • e5485a9958 Updated doc Bernardo Damele 2010-10-20 22:14:52 +0000
  • d8bfa76dca Minor possible bug fix Bernardo Damele 2010-10-20 22:12:53 +0000
  • e73e06069b Minor code refactoring Bernardo Damele 2010-10-20 22:09:03 +0000
  • 862cc9ac53 Minor cosmetic fixes Bernardo Damele 2010-10-20 21:58:33 +0000
  • 22ed09a358 Updated Bernardo Damele 2010-10-20 21:52:33 +0000
  • 3b5c5cc457 Minor possible bug fix Bernardo Damele 2010-10-20 21:49:05 +0000
  • f95098693f Removed unused functions Bernardo Damele 2010-10-20 21:16:28 +0000
  • 430bb7478f Minor bug fix Bernardo Damele 2010-10-20 21:15:06 +0000
  • 34f70657ee fix for NULL values Miroslav Stampar 2010-10-20 10:29:18 +0000
  • 00449f1402 fix/upgrade/chicken soup Miroslav Stampar 2010-10-20 09:54:17 +0000
  • e24bff0497 nice refactoring Miroslav Stampar 2010-10-20 09:46:57 +0000
  • 5d3cbec457 no more regex. web server independent. Miroslav Stampar 2010-10-20 09:35:46 +0000
  • 934adb5e8d code refactoring Miroslav Stampar 2010-10-20 09:09:04 +0000
  • b032fdbf74 added randInt to error injection vectors Miroslav Stampar 2010-10-20 08:56:58 +0000
  • dabbcf9e23 fix for that 'Subquery returns more than 1 row' Miroslav Stampar 2010-10-20 08:50:05 +0000
  • 82f44989ce update of error based injection and bug fix for --roles on MSSQL server Miroslav Stampar 2010-10-20 06:40:33 +0000
  • f2dae98448 fix for MySQL error queries Miroslav Stampar 2010-10-19 23:30:08 +0000
  • 0817d1b78d Cosmetics Bernardo Damele 2010-10-19 23:09:30 +0000
  • 8776db872c minor refactoring Miroslav Stampar 2010-10-19 23:05:24 +0000
  • 1b376c99a6 removed temp dictionary and replaced with kb.misc Miroslav Stampar 2010-10-19 23:00:19 +0000
  • 813f44da16 Minor bug fix for MSSQL connector --tables option Bernardo Damele 2010-10-19 22:11:17 +0000
  • 7927e97007 update Miroslav Stampar 2010-10-19 18:34:57 +0000
  • 415524bd5a remove --error, now it's only --error-test (it needs to return True to be able to use it) Miroslav Stampar 2010-10-19 18:34:14 +0000
  • 8d9201a3dc minor update Miroslav Stampar 2010-10-19 18:23:21 +0000
  • 4009ef385e more update regarding error based injection support Miroslav Stampar 2010-10-19 18:17:34 +0000
  • b2e0b615f8 fix for that MySQL checking Miroslav Stampar 2010-10-19 17:38:39 +0000
  • 34d7de1d46 cosmetics Miroslav Stampar 2010-10-19 15:28:54 +0000
  • d7622bb9cf major fix for MySQL error based injections Miroslav Stampar 2010-10-19 15:17:16 +0000
  • 1fce9683f8 now --users work for MSSQL too Miroslav Stampar 2010-10-19 15:05:32 +0000
  • 80505de15b now --users work on Oracle and Postgre (tested) Miroslav Stampar 2010-10-19 14:56:57 +0000
  • 4bc541ec3c error based update Miroslav Stampar 2010-10-19 14:47:13 +0000
  • d0ebe428da i've left error flag Miroslav Stampar 2010-10-19 14:12:34 +0000
  • bf850af2d8 fix for Oracle error based query "space" problem Miroslav Stampar 2010-10-19 14:10:09 +0000
  • 878135fe40 minor fix Miroslav Stampar 2010-10-19 14:00:27 +0000
  • 6a8b1046d4 first successfull run of error based sqlmap in history :). tested --banner, --current-user, --current-db on 4 major DBMSes. still hidden from users (turn on flag error in getValue() in inject.py) Miroslav Stampar 2010-10-19 12:02:04 +0000
  • 0c286d8db2 minor update Miroslav Stampar 2010-10-19 09:17:01 +0000
  • ccda92536f added header Miroslav Stampar 2010-10-19 09:13:30 +0000
  • 264e0a6fda added support for displaying revision number at unhandled exception message Miroslav Stampar 2010-10-19 08:55:14 +0000
  • 9a7fd29d4f using pushValue and popValue Miroslav Stampar 2010-10-18 22:22:41 +0000
  • a97319656c optimization - now if DBMS was detected by error based HTML parser, then it's moved at the first place for testing Miroslav Stampar 2010-10-18 21:47:11 +0000
  • 729156e91c proper fix Miroslav Stampar 2010-10-18 21:39:46 +0000
  • 3d5494845c minor bug fix Miroslav Stampar 2010-10-18 21:32:50 +0000
  • d123bb741a added error based queries for MySQL, Postgre, MS SQL and Oracle Miroslav Stampar 2010-10-18 21:26:13 +0000
  • 8b8fff41fe cosmetics (adding html parsed DBMS) regarding heuristic check Miroslav Stampar 2010-10-18 12:11:16 +0000
  • 955ae5cd2e Fixed svn:keywords Bernardo Damele 2010-10-18 12:09:59 +0000
  • 351a7f5769 setting property Id Miroslav Stampar 2010-10-18 11:43:00 +0000
  • 3570b4a705 minor fix Miroslav Stampar 2010-10-18 11:41:17 +0000
  • fff7fe83c1 new tamper script Miroslav Stampar 2010-10-18 11:39:28 +0000
  • 1d74036ee3 Minor cosmetic fixes Bernardo Damele 2010-10-18 11:34:53 +0000
  • 1a9aabf49d Minor fix Bernardo Damele 2010-10-18 10:40:05 +0000
  • c6cd8ae72b Added another tamper script Bernardo Damele 2010-10-18 10:34:38 +0000
  • 36bc410333 Minor bug fix Bernardo Damele 2010-10-18 09:50:23 +0000
  • 6b70dadfb2 minor cosmetics Miroslav Stampar 2010-10-18 09:09:22 +0000
  • 149837ebf5 added the same for proxy authorization header Miroslav Stampar 2010-10-18 09:02:56 +0000
  • aaebb4336e fix for Bug #202 Miroslav Stampar 2010-10-18 08:54:08 +0000
  • 683184cc8f Minor refactoring Bernardo Damele 2010-10-17 21:06:52 +0000
  • 60a1b48194 Major bug fix for --os-pwn Bernardo Damele 2010-10-17 20:44:16 +0000
  • 73ececd903 added that "default" "Connection: keep-alive" header Miroslav Stampar 2010-10-17 06:44:54 +0000
  • cd0fe8dde0 Updated sample configuration file and cmdline help Bernardo Damele 2010-10-17 00:07:53 +0000
  • 64b9f94fcf Renamed --common-prediction switch to --predict-output Bernardo Damele 2010-10-16 23:50:13 +0000
  • f54c134d22 Minor adjustment Bernardo Damele 2010-10-16 22:43:05 +0000
  • 6211915da5 Cosmetic fix Bernardo Damele 2010-10-16 22:31:16 +0000
  • cfa5655150 Updated changelog Bernardo Damele 2010-10-16 22:23:53 +0000
  • 7b71262de6 Cosmetic fix Bernardo Damele 2010-10-16 22:07:29 +0000
  • a2997a6dce Minor bug fix to --tamper Bernardo Damele 2010-10-16 21:55:34 +0000
  • 2129935e06 Split character for tamper scripts (--tamper option) is now comma, not semi-colon. Minor enhancement Bernardo Damele 2010-10-16 21:52:16 +0000
  • 2dae934a2b Minor bug fixes, code refactoring and enhanced --tamper functionality Bernardo Damele 2010-10-16 21:33:15 +0000
  • 5c3d21065a bug fix (reported by nightman) Miroslav Stampar 2010-10-16 21:29:35 +0000
  • 2b60304933 update Miroslav Stampar 2010-10-16 21:19:44 +0000
  • 84ed7f192a Cosmetic fixes Bernardo Damele 2010-10-16 15:10:48 +0000
  • 1336b97c2c removed --useBetween switch and added new tampering module ./tamper/between.py Miroslav Stampar 2010-10-15 23:48:07 +0000
  • 1ae4d0fc2a added optimization group Miroslav Stampar 2010-10-15 23:26:48 +0000
  • e7c8be1d45 Minor layout adjustments Bernardo Damele 2010-10-15 15:37:15 +0000
  • c9f0c75030 removed --space (usage of tampering modules is now a prefered way to do it) Miroslav Stampar 2010-10-15 12:52:33 +0000
  • d0514d18ec removed that spaces from URI payloads Miroslav Stampar 2010-10-15 12:49:03 +0000
  • bf56f8c63c Cosmetic fix Bernardo Damele 2010-10-15 12:46:41 +0000
  • dcb9c2103a just in case update Miroslav Stampar 2010-10-15 11:20:19 +0000