Commit Graph

  • 24d3e24db0 more updates regarding --os-shell feature Miroslav Stampar 2010-02-25 12:16:49 +0000
  • b558712a47 more feature updates Miroslav Stampar 2010-02-25 11:40:49 +0000
  • 15d1fcbb7f now runcmd exe has random name too Miroslav Stampar 2010-02-25 10:47:12 +0000
  • bad2acdcb9 some minor command output adjustment Miroslav Stampar 2010-02-25 10:39:15 +0000
  • 2cafd5697b new changes regarding --os-shell Miroslav Stampar 2010-02-25 10:33:41 +0000
  • 858cb25975 update Miroslav Stampar 2010-02-24 23:40:56 +0000
  • 0795e1164d Removed ignore of deprecation warning, dealt with it in convert.py Bernardo Damele 2010-02-23 09:37:10 +0000
  • 4bea0e343a Avoiding md5/sha1 deprecated warning in Python >=2.6 Miroslav Stampar 2010-02-23 08:54:33 +0000
  • 8f26f30740 revert changes Miroslav Stampar 2010-02-22 14:35:08 +0000
  • ad0def7604 fix (pretty sure :) Miroslav Stampar 2010-02-22 14:13:32 +0000
  • 7e5a980f1b __asm keyword is not supported by Win64 (we'll need to find a solution for this). This keyword _M_IX86 is only defined on Win32. Miroslav Stampar 2010-02-22 14:02:13 +0000
  • ccec743ba1 Minor adjustments to README files Bernardo Damele 2010-02-21 19:12:41 +0000
  • e05785fef6 Recompiled MySQL/Linux shared object, optimized for size (-Os) Bernardo Damele 2010-02-21 18:01:54 +0000
  • 16edd18a03 modifications Miroslav Stampar 2010-02-21 09:18:44 +0000
  • 60366f7168 new program for running command prompt commands Miroslav Stampar 2010-02-21 08:52:54 +0000
  • 9c014c0fd0 minor change Miroslav Stampar 2010-02-20 23:11:05 +0000
  • 2a07af2294 removed pdb tracing Miroslav Stampar 2010-02-20 22:36:17 +0000
  • 0debc95ad4 some fixes Miroslav Stampar 2010-02-20 22:31:54 +0000
  • 3c34066d19 Added newly compiled PostgreSQL UDFs for Windows Bernardo Damele 2010-02-20 20:59:13 +0000
  • af1d9f129c Recompiled and tested PostgreSQL shared object (Linux) optimized for size (gcc flag -Os). Bernardo Damele 2010-02-20 19:10:55 +0000
  • d1e3596382 Minor UPX adjustment Bernardo Damele 2010-02-20 19:02:55 +0000
  • 6267e74bfb Added newly compiled PostgreSQL UDFs for Linux Bernardo Damele 2010-02-19 23:29:27 +0000
  • b28aeef8ff Aligned PostgreSQL shared object source code for Linux Bernardo Damele 2010-02-19 17:11:17 +0000
  • 3fea964538 fix, finally.... Miroslav Stampar 2010-02-19 16:44:37 +0000
  • 16599cf2cf typo fix Bernardo Damele 2010-02-16 22:54:22 +0000
  • 0ed5ba5559 minor update Miroslav Stampar 2010-02-16 13:24:09 +0000
  • c4951fd631 some updates regarding --os-shell option Miroslav Stampar 2010-02-16 13:20:34 +0000
  • b5deab1e43 added some basic error handling for it to be more user friendly Miroslav Stampar 2010-02-15 12:46:03 +0000
  • 6db0905137 some fixes regarding caveats part of article at http://www.postgresql.org/docs/6.3/static/c3102.htm Miroslav Stampar 2010-02-14 19:37:20 +0000
  • 1d55923c9d some fixes regarding caveats part of article at http://www.postgresql.org/docs/6.3/static/c3102.htm Miroslav Stampar 2010-02-14 19:36:02 +0000
  • 8131f9c77c Added and fixed README files Bernardo Damele 2010-02-12 00:20:53 +0000
  • 7e0c411c0e Updated THANKS file Bernardo Damele 2010-02-11 23:46:50 +0000
  • dc06b40ddc Minor exception message fix Bernardo Damele 2010-02-11 23:07:33 +0000
  • 89dc99188d --read-file on PostgreSQL now relies on the new sys_fileread() UDF so that also binary files can be read. Fixed a minor bug in custom UDF injection feature --udf-inject. Major code refactoring. Bernardo Damele 2010-02-11 22:57:50 +0000
  • f728208ff7 Minor cosmetic fix Bernardo Damele 2010-02-10 15:51:52 +0000
  • cef248a5ea update for that invalid target url Otavio Augusto reported Miroslav Stampar 2010-02-10 12:06:23 +0000
  • 203cfd114f changed raised exception type Miroslav Stampar 2010-02-10 09:39:36 +0000
  • 8e8f6f842c fix for that md5 error reported by Dani (lgrecol@gmail.com) Miroslav Stampar 2010-02-10 09:27:34 +0000
  • 00a23ace9a some changes regarding web takeover Miroslav Stampar 2010-02-09 14:27:41 +0000
  • 542b01993e minor fix regarding exception handling of multi-part post handler Miroslav Stampar 2010-02-09 14:02:47 +0000
  • a6674edf8a regular expressions revisited Miroslav Stampar 2010-02-09 13:01:08 +0000
  • 6a5a5d55f2 fix for that --stacked-test error reported by dsu@dsu.com.ua Miroslav Stampar 2010-02-09 11:27:42 +0000
  • 212cd828d6 new and working asp uploader Miroslav Stampar 2010-02-08 17:07:09 +0000
  • bc0eb880df fix for that -- bug Miroslav Stampar 2010-02-08 11:44:32 +0000
  • 4e6af8d6c9 some syntax corrections Miroslav Stampar 2010-02-08 09:10:32 +0000
  • 5c92fad5dc Avoid to check for existence of not needed UDFs and minor code adjustment for cleanup() method Bernardo Damele 2010-02-05 23:14:16 +0000
  • b08a4efb4b Minor layout adjustments Bernardo Damele 2010-02-04 17:45:56 +0000
  • 22995787d1 Updated THANKS file Bernardo Damele 2010-02-04 15:24:13 +0000
  • d291464cd4 code refactoring regarding path normalization Miroslav Stampar 2010-02-04 14:50:54 +0000
  • dbd52c52e4 minor fix Miroslav Stampar 2010-02-04 14:39:24 +0000
  • ec63fc4036 code refactoring - added functions posixToNtSlashes and ntToPosixSlashes Miroslav Stampar 2010-02-04 14:37:00 +0000
  • a1e80e77a1 fix for HTTP_POST_FILES issue ( added if (phpversion() < '4.1.0')...else... ) Miroslav Stampar 2010-02-04 13:08:48 +0000
  • 87239476af more fixes :) Miroslav Stampar 2010-02-04 10:10:41 +0000
  • e4699f389d some bug fixes regarding --os-shell usage against windows servers Miroslav Stampar 2010-02-04 09:49:31 +0000
  • ea045eaa2f fixed serious issue with adding file paths into kb.absFilePaths (dirname was wrongly added, and afterwards getDirs used dirname of dirname) also, fixed some issues with Windows paths Miroslav Stampar 2010-02-03 16:40:12 +0000
  • 7c88e32f9d bug fix for 404 program termination during shell upload attempt Miroslav Stampar 2010-02-03 16:16:34 +0000
  • 565433097e used normalizePath instead of os.path.normalize Miroslav Stampar 2010-02-03 16:10:09 +0000
  • 494e014a4a minor update Miroslav Stampar 2010-02-03 16:04:44 +0000
  • 8b0d31a6b7 fix for cases where both posix and nt path versions of windows paths are in parsed web page Miroslav Stampar 2010-02-03 15:34:20 +0000
  • 894b9f0f80 minor minor update Miroslav Stampar 2010-02-03 15:15:30 +0000
  • 25f1a9c7d0 upgrade of web directory parsing for things like C:/xampp/htdocs/sqlmap/mysql/get_int.php (XAMPP uses this) Miroslav Stampar 2010-02-03 15:06:41 +0000
  • 87c8bdbc29 removed pdb tracing Miroslav Stampar 2010-02-03 14:52:29 +0000
  • c74b920f54 bug fix Miroslav Stampar 2010-02-03 14:49:28 +0000
  • 950dba5139 Minor bug fix for --start and --stop Bernardo Damele 2010-02-02 14:17:39 +0000
  • 9ed0744510 Added some error messages to detect back-end DBMS Bernardo Damele 2010-01-30 22:24:20 +0000
  • 267cf5dd1a Updated documentation Bernardo Damele 2010-01-30 00:08:10 +0000
  • 7faefcca88 Minor logging messages adjustments Bernardo Damele 2010-01-29 23:19:52 +0000
  • 979c919dc7 Minor logging message adjustment Bernardo Damele 2010-01-29 22:58:12 +0000
  • e8b0fd90c8 Minor bug fix Bernardo Damele 2010-01-29 19:32:02 +0000
  • 767c67e37a --priv-esc now relieas on more powerful and complete getsystem Meterpreter command that also implements kitrap0d as 4th technique Bernardo Damele 2010-01-29 14:57:33 +0000
  • c20b196518 not sure that svn added binary flag automatically to this file (done it manually) Miroslav Stampar 2010-01-29 10:18:17 +0000
  • 061794650f minor fix Miroslav Stampar 2010-01-29 10:15:05 +0000
  • 92817159dc cloaked upx for windows (used mkstemp because of execution and file access rights problem) Miroslav Stampar 2010-01-29 10:12:09 +0000
  • 200518724c By default do not use Churrasco, but still let the user choose it. The default technique to privilege escalate the OS user to SYSTEM when --priv-esc is provided now it 'run kitrap0d'. Bernardo Damele 2010-01-29 02:27:50 +0000
  • 7b8316728c Major bug fix in takeover functionalities on Microsoft SQL Server Bernardo Damele 2010-01-29 00:09:05 +0000
  • c6cae7da41 Updated changelog Bernardo Damele 2010-01-28 23:10:54 +0000
  • 144dc1b8c4 Show proper warning message when --priv-esc is provided and underlying OS is not Windows Bernardo Damele 2010-01-28 17:22:17 +0000
  • 6f5d2ed171 Minor cosmetic adjustments Bernardo Damele 2010-01-28 17:07:34 +0000
  • a2077bfc0e quick fix Miroslav Stampar 2010-01-28 16:56:00 +0000
  • 732ed48e2b some refactoring regarding decloaking Miroslav Stampar 2010-01-28 16:50:34 +0000
  • dcbbad642d Minor self fix, switched to rc6 Bernardo Damele 2010-01-28 10:27:47 +0000
  • f6b447f6e7 fix for "NameError: global name 'webFileStreamUpload' is not defined" Miroslav Stampar 2010-01-28 08:54:47 +0000
  • a20bbc3974 Removed carriage return (\r) from UDFs shared library source code Bernardo Damele 2010-01-28 01:16:01 +0000
  • 645afee359 some changes Miroslav Stampar 2010-01-28 00:25:36 +0000
  • 921e449454 added support for cloaking Churrasco.exe file Miroslav Stampar 2010-01-28 00:07:33 +0000
  • 4559ded6c1 added new line at the end of the file Miroslav Stampar 2010-01-27 17:02:23 +0000
  • f4b8ce5c72 fix for 'No such file or directory' OSError exception Miroslav Stampar 2010-01-27 17:00:54 +0000
  • 00002eeb38 bad grammar fix Miroslav Stampar 2010-01-27 16:05:32 +0000
  • d0acb1c5a3 another fix. hope it works :) Miroslav Stampar 2010-01-27 16:01:50 +0000
  • f8056f4098 quick fix regarding usage of StringIO instead of file stream Miroslav Stampar 2010-01-27 15:44:35 +0000
  • a0eabb6719 Id property set Miroslav Stampar 2010-01-27 14:28:34 +0000
  • 8a8dc73980 more fixes Miroslav Stampar 2010-01-27 14:27:11 +0000
  • 1d15c595a4 minor fix Miroslav Stampar 2010-01-27 14:08:09 +0000
  • e63428207c modified a way to handle shell scripts Miroslav Stampar 2010-01-27 13:59:25 +0000
  • f91687c4f7 removed old plain text shell scripts Miroslav Stampar 2010-01-27 13:58:28 +0000
  • 6966c235a4 removed junk file Miroslav Stampar 2010-01-27 13:57:19 +0000
  • 93b7994c0c added new cloaking functionality for shell scripts Miroslav Stampar 2010-01-27 13:56:26 +0000
  • a78bf9a88b new files Miroslav Stampar 2010-01-27 13:55:13 +0000
  • 6437c16156 run kitrap0d script along with listing Windows Impersonation Tokens via meterpreter's incognito extension when --priv-esc is provided (see #149). Bernardo Damele 2010-01-26 01:14:44 +0000
  • a97e20d8e1 Added proper svn:keywords Bernardo Damele 2010-01-25 11:03:23 +0000