Commit Graph

  • bfc12e93c5 ms access returns -1 for True Miroslav Stampar 2010-03-30 11:33:51 +0000
  • ae3455a0c2 more update Miroslav Stampar 2010-03-30 11:28:14 +0000
  • 738c210075 update Miroslav Stampar 2010-03-30 11:21:26 +0000
  • 87d8c6719e updates, fixes and stuff Miroslav Stampar 2010-03-30 11:06:30 +0000
  • f04449be03 update Miroslav Stampar 2010-03-29 23:48:21 +0000
  • 4dd2cdef47 update Miroslav Stampar 2010-03-27 23:48:12 +0000
  • a0290a257b Added support to connect directly also to Oracle - see #158 Bernardo Damele 2010-03-27 21:50:19 +0000
  • 1416cd0d86 Major enhancement to directly connect to the dbms without passing via a sql injection: adapted code accordingly - see #158. This feature relies on python third-party libraries to be able to connect to the database. For the moment it has been implemented for MySQL (with python-mysqldb module) and PostgreSQL (with python-psycopg2 module). Minor layout adjustments. Bernardo Damele 2010-03-26 23:23:25 +0000
  • 4ca1adba2c update Miroslav Stampar 2010-03-26 21:30:36 +0000
  • 1ec5221d82 minor update Miroslav Stampar 2010-03-26 20:51:55 +0000
  • eaa9dd07bc Minor bug fix for --roles Bernardo Damele 2010-03-26 20:45:22 +0000
  • 0aa8f7309b added copyright notice and keywords Miroslav Stampar 2010-03-26 20:23:08 +0000
  • 2e05e1c54d new module for Feature #61 Miroslav Stampar 2010-03-26 20:19:18 +0000
  • 8bab94de64 added two new functions: isBase64EncodedString and isHexEncodedString for Feature #71 Miroslav Stampar 2010-03-26 17:18:02 +0000
  • 5a6a01f24c added socket timeout exception handling regarding that timeout message from Fahad Al Shunaiber Miroslav Stampar 2010-03-26 11:51:23 +0000
  • be81c20298 Minor layout adjustment Bernardo Damele 2010-03-25 16:26:50 +0000
  • 2aadc5c939 Added support for --roles (for Oracle ROLE_PRIVS). Enhanced Oracle --privileges to fall-back to USER_SYS_PRIVS if DBA_SYS_PRIVS is not accessible (so session user is not DBA) - Fixes ticket #180. Minor enhancement to Firebird to determine if a DB user is a DBA. Minor code refactoring. Bernardo Damele 2010-03-25 15:46:06 +0000
  • f4f68218bc Minor layout adjustment for --threads and --eta output Bernardo Damele 2010-03-25 11:47:18 +0000
  • a63e251b25 Ahead with code refactoring, related to r1502. Fixed svn:keywords propset to all .py files. Bernardo Damele 2010-03-23 21:26:45 +0000
  • f0f1176396 Updated THANKS Bernardo Damele 2010-03-23 21:24:31 +0000
  • 8e57767c48 Fixes #180 - properly url encode sqlmap payload in POST/Cookie too, like for GET Bernardo Damele 2010-03-23 10:27:39 +0000
  • 09768a7b62 Major code refactoring: moved and split plugins (mysql, pgsql, mssql, oracle) more granularly and organized. Todo for firebird, sqlite, access. Bernardo Damele 2010-03-22 22:57:57 +0000
  • f9a135e232 Minor bug fix and layout adjustment regarding --threading and standard output Bernardo Damele 2010-03-22 17:38:19 +0000
  • 9e8a108768 Updated Bernardo Damele 2010-03-22 15:43:38 +0000
  • d13ad8b2d7 fixes #181 - proper save/resume information about single entry UNION SQL injection Bernardo Damele 2010-03-22 15:39:29 +0000
  • d00e4a458a Code cleanup Bernardo Damele 2010-03-21 00:39:44 +0000
  • 72f3674844 Minor bug fix Bernardo Damele 2010-03-18 17:36:58 +0000
  • 0d559d14df Initial support for SQLite (90% approx). Initial support for Firebird (30% approx). Initial support for Access (10% approx). Shared libraries code/installation scripts ported to 64bit, directory structure adapted. Minor code adjustments. Bernardo Damele 2010-03-18 17:20:54 +0000
  • f1fde2e443 added basic skeleton for FAQ doc Miroslav Stampar 2010-03-17 12:56:26 +0000
  • d2f86fb0a5 Fixes #172 - also cookies are parsed from burp/webscarab logs (-l) and request file (-r) now Bernardo Damele 2010-03-16 15:21:42 +0000
  • 466df89c4a Fixes #178 and #179 - proper handling of custom redirects Bernardo Damele 2010-03-16 14:30:57 +0000
  • 3b3353e05b Revert last commit Bernardo Damele 2010-03-16 13:56:36 +0000
  • 1dfe558d3d Fix for Issue #177 Miroslav Stampar 2010-03-16 13:11:44 +0000
  • 323cf2b7f2 Fixes #177 - Don't exit at exception if in "multiple targets" mode (-l or -g) Bernardo Damele 2010-03-16 12:14:02 +0000
  • 6d0ea86414 Fixes #59 - proper customizable redirect (302 and 301) Bernardo Damele 2010-03-15 14:24:43 +0000
  • 417f7fae00 Fix for "bug: -g uses wrong session file" Miroslav Stampar 2010-03-15 12:02:04 +0000
  • 8af7d6c58b minor cosmetic update Miroslav Stampar 2010-03-15 11:55:13 +0000
  • a0ec447b7d fix for Issue #170 Miroslav Stampar 2010-03-15 11:33:34 +0000
  • 7f5bc5e3fe Increased version to 0.9-dev Bernardo Damele 2010-03-15 11:04:57 +0000
  • 5063401130 Minor bug fix, fixes #170 Bernardo Damele 2010-03-15 11:00:14 +0000
  • 572b6fd920 sqlmap 0.8 stable! 0.8 Bernardo Damele 2010-03-15 01:17:27 +0000
  • bfbf58b04e Generated new user's manual html and pdf Bernardo Damele 2010-03-13 22:07:08 +0000
  • ee89709042 Updated manual Bernardo Damele 2010-03-13 21:56:38 +0000
  • ba6172a381 Added: svn:keywords Miroslav Stampar 2010-03-13 17:30:16 +0000
  • a6ab42c873 new file with getch() method which we'll use for good samaritan feature Miroslav Stampar 2010-03-13 17:28:23 +0000
  • 4bef12a2b4 doc update Miroslav Stampar 2010-03-13 14:35:56 +0000
  • 5f76d27779 minor typo correction Miroslav Stampar 2010-03-13 10:44:24 +0000
  • 4c6c91a80b another --reg-read fix Miroslav Stampar 2010-03-12 23:12:06 +0000
  • c42c4982c3 Updated documentation according to r1460 Bernardo Damele 2010-03-12 22:59:03 +0000
  • 7d8cc1a482 Get rid of Churrasco (Token kidnapping technique to --priv-esc). Reasons why: 1. there's kitrap0d (MS10-015) which is far more reliable, just recently fixed 2. works only to priv esc basically on MSSQL when it runs as NETWORK SERVICE and the machine is not patched against MS09-012 which is "rare" (hopefully) nowadays. Now sqlmap relies on kitrap0d and incognito to privilege escalate the database process' user privileges to SYSTEM, both via Meterpreter. Bernardo Damele 2010-03-12 22:43:35 +0000
  • 6b1ae62753 final fix for reading registry keys (now both parse and non-parse reads work fine) Miroslav Stampar 2010-03-12 22:26:06 +0000
  • 0a2fe651ab some fixes regarding registry reading Miroslav Stampar 2010-03-12 22:09:58 +0000
  • 054a4aaee7 Updated documentation, almost ready for 0.8 release! Bernardo Damele 2010-03-12 17:43:38 +0000
  • 25f8a72414 Minor layout adjustment Bernardo Damele 2010-03-12 14:48:33 +0000
  • 17d0b82fee two dots instead of three Miroslav Stampar 2010-03-12 14:31:14 +0000
  • e8d76994ba Minor bug fix to avoid resuming data filled into the sqlmap support tables Bernardo Damele 2010-03-12 14:30:21 +0000
  • 18d1d09f1c Minor bug fix Bernardo Damele 2010-03-12 13:34:46 +0000
  • 15c638ac52 some beautification Miroslav Stampar 2010-03-12 13:07:07 +0000
  • 7ec04281dd minor adjustments Miroslav Stampar 2010-03-12 12:46:26 +0000
  • fffda32f76 fix for Bug #167 Miroslav Stampar 2010-03-12 12:38:19 +0000
  • f6adb431e6 Minor layout adjustment and typo fix Bernardo Damele 2010-03-12 12:23:05 +0000
  • b50a2288f4 Minor layout adjustments Bernardo Damele 2010-03-11 23:54:07 +0000
  • 506403dd9d Improved PHP backdoor Bernardo Damele 2010-03-11 16:55:38 +0000
  • ec43419ad1 minor makeup fix Miroslav Stampar 2010-03-11 11:20:52 +0000
  • 2c053d5cfb fix for Bug #166 (Keyboard interrupt in Python threading) Miroslav Stampar 2010-03-11 11:14:20 +0000
  • b344a70ba1 Updated changelog Bernardo Damele 2010-03-11 01:10:55 +0000
  • 4d53b17320 Updated THANKS Bernardo Damele 2010-03-10 22:08:54 +0000
  • fdf417f57e Minor adjustment and bug fix Bernardo Damele 2010-03-10 22:08:11 +0000
  • 91dd609e26 fixed threading bug (difflib :) Miroslav Stampar 2010-03-10 14:14:27 +0000
  • 6712b19df2 Updated ChangeLog Bernardo Damele 2010-03-10 01:14:23 +0000
  • cc611c0010 Minor layout adjustments Bernardo Damele 2010-03-09 22:14:26 +0000
  • 3f3ddd5437 fix for that SELECT DISTINCT(LENGTH(...)) "misbehavior" Miroslav Stampar 2010-03-09 13:14:43 +0000
  • 8593741358 Minor bug fix Bernardo Damele 2010-03-05 15:25:53 +0000
  • 7136c17f19 Minor log adjustments Bernardo Damele 2010-03-05 14:59:33 +0000
  • d618964ab6 more time adjustments Miroslav Stampar 2010-03-05 14:30:50 +0000
  • 45fc58d267 update Miroslav Stampar 2010-03-05 14:24:54 +0000
  • 071e897f4e minor time adjustments Miroslav Stampar 2010-03-05 14:09:20 +0000
  • 6fd1f7f77c update Miroslav Stampar 2010-03-05 14:06:03 +0000
  • 20d8275f0e Minor doc adjustment Bernardo Damele 2010-03-05 10:20:45 +0000
  • 5209b5929f update Bernardo Damele 2010-03-04 17:38:00 +0000
  • 5bd8504f21 Newline adjustment Bernardo Damele 2010-03-04 14:23:52 +0000
  • 5334a40451 added description for --flush-session option Miroslav Stampar 2010-03-04 13:17:11 +0000
  • 58d54b6515 added new option --flush-session Miroslav Stampar 2010-03-04 13:01:18 +0000
  • a839566bb2 Added a link Bernardo Damele 2010-03-04 12:44:23 +0000
  • 31a2fad530 Extended copyright to 2010 Bernardo Damele 2010-03-04 10:47:31 +0000
  • 476e389d38 Extended copyright to 2010 Bernardo Damele 2010-03-04 10:41:33 +0000
  • 8663b5b68b minor fixes Miroslav Stampar 2010-03-04 09:16:45 +0000
  • b544405878 fixed some issue involving banner parsing Miroslav Stampar 2010-03-04 09:15:26 +0000
  • 63880e3121 update Bernardo Damele 2010-03-03 22:02:48 +0000
  • ef7666c12b Minor code cleanup Bernardo Damele 2010-03-03 19:23:43 +0000
  • 1c7943f7b1 Update Bernardo Damele 2010-03-03 18:58:27 +0000
  • 9adeaa6191 Code cleanup Bernardo Damele 2010-03-03 18:57:09 +0000
  • 1704c73892 Update Bernardo Damele 2010-03-03 16:25:03 +0000
  • a654a426ef Minor adjustments Bernardo Damele 2010-03-03 16:19:17 +0000
  • 156fdd96ef Updated copyright Bernardo Damele 2010-03-03 15:26:27 +0000
  • e774578180 Updated documentation Bernardo Damele 2010-03-03 15:16:43 +0000
  • 49aa1ae542 some fix/revert of mssql banner file Miroslav Stampar 2010-03-03 14:37:57 +0000
  • 759b720425 documentation update Miroslav Stampar 2010-03-03 13:59:29 +0000
  • 415d5f2b44 minor update Miroslav Stampar 2010-03-03 13:49:24 +0000
  • f941159f81 Updated MSSQL xml signatures file Miroslav Stampar 2010-03-03 13:46:12 +0000