Commit Graph

  • bc0eb880df fix for that -- bug Miroslav Stampar 2010-02-08 11:44:32 +0000
  • 4e6af8d6c9 some syntax corrections Miroslav Stampar 2010-02-08 09:10:32 +0000
  • 5c92fad5dc Avoid to check for existence of not needed UDFs and minor code adjustment for cleanup() method Bernardo Damele 2010-02-05 23:14:16 +0000
  • b08a4efb4b Minor layout adjustments Bernardo Damele 2010-02-04 17:45:56 +0000
  • 22995787d1 Updated THANKS file Bernardo Damele 2010-02-04 15:24:13 +0000
  • d291464cd4 code refactoring regarding path normalization Miroslav Stampar 2010-02-04 14:50:54 +0000
  • dbd52c52e4 minor fix Miroslav Stampar 2010-02-04 14:39:24 +0000
  • ec63fc4036 code refactoring - added functions posixToNtSlashes and ntToPosixSlashes Miroslav Stampar 2010-02-04 14:37:00 +0000
  • a1e80e77a1 fix for HTTP_POST_FILES issue ( added if (phpversion() < '4.1.0')...else... ) Miroslav Stampar 2010-02-04 13:08:48 +0000
  • 87239476af more fixes :) Miroslav Stampar 2010-02-04 10:10:41 +0000
  • e4699f389d some bug fixes regarding --os-shell usage against windows servers Miroslav Stampar 2010-02-04 09:49:31 +0000
  • ea045eaa2f fixed serious issue with adding file paths into kb.absFilePaths (dirname was wrongly added, and afterwards getDirs used dirname of dirname) also, fixed some issues with Windows paths Miroslav Stampar 2010-02-03 16:40:12 +0000
  • 7c88e32f9d bug fix for 404 program termination during shell upload attempt Miroslav Stampar 2010-02-03 16:16:34 +0000
  • 565433097e used normalizePath instead of os.path.normalize Miroslav Stampar 2010-02-03 16:10:09 +0000
  • 494e014a4a minor update Miroslav Stampar 2010-02-03 16:04:44 +0000
  • 8b0d31a6b7 fix for cases where both posix and nt path versions of windows paths are in parsed web page Miroslav Stampar 2010-02-03 15:34:20 +0000
  • 894b9f0f80 minor minor update Miroslav Stampar 2010-02-03 15:15:30 +0000
  • 25f1a9c7d0 upgrade of web directory parsing for things like C:/xampp/htdocs/sqlmap/mysql/get_int.php (XAMPP uses this) Miroslav Stampar 2010-02-03 15:06:41 +0000
  • 87c8bdbc29 removed pdb tracing Miroslav Stampar 2010-02-03 14:52:29 +0000
  • c74b920f54 bug fix Miroslav Stampar 2010-02-03 14:49:28 +0000
  • 950dba5139 Minor bug fix for --start and --stop Bernardo Damele 2010-02-02 14:17:39 +0000
  • 9ed0744510 Added some error messages to detect back-end DBMS Bernardo Damele 2010-01-30 22:24:20 +0000
  • 267cf5dd1a Updated documentation Bernardo Damele 2010-01-30 00:08:10 +0000
  • 7faefcca88 Minor logging messages adjustments Bernardo Damele 2010-01-29 23:19:52 +0000
  • 979c919dc7 Minor logging message adjustment Bernardo Damele 2010-01-29 22:58:12 +0000
  • e8b0fd90c8 Minor bug fix Bernardo Damele 2010-01-29 19:32:02 +0000
  • 767c67e37a --priv-esc now relieas on more powerful and complete getsystem Meterpreter command that also implements kitrap0d as 4th technique Bernardo Damele 2010-01-29 14:57:33 +0000
  • c20b196518 not sure that svn added binary flag automatically to this file (done it manually) Miroslav Stampar 2010-01-29 10:18:17 +0000
  • 061794650f minor fix Miroslav Stampar 2010-01-29 10:15:05 +0000
  • 92817159dc cloaked upx for windows (used mkstemp because of execution and file access rights problem) Miroslav Stampar 2010-01-29 10:12:09 +0000
  • 200518724c By default do not use Churrasco, but still let the user choose it. The default technique to privilege escalate the OS user to SYSTEM when --priv-esc is provided now it 'run kitrap0d'. Bernardo Damele 2010-01-29 02:27:50 +0000
  • 7b8316728c Major bug fix in takeover functionalities on Microsoft SQL Server Bernardo Damele 2010-01-29 00:09:05 +0000
  • c6cae7da41 Updated changelog Bernardo Damele 2010-01-28 23:10:54 +0000
  • 144dc1b8c4 Show proper warning message when --priv-esc is provided and underlying OS is not Windows Bernardo Damele 2010-01-28 17:22:17 +0000
  • 6f5d2ed171 Minor cosmetic adjustments Bernardo Damele 2010-01-28 17:07:34 +0000
  • a2077bfc0e quick fix Miroslav Stampar 2010-01-28 16:56:00 +0000
  • 732ed48e2b some refactoring regarding decloaking Miroslav Stampar 2010-01-28 16:50:34 +0000
  • dcbbad642d Minor self fix, switched to rc6 Bernardo Damele 2010-01-28 10:27:47 +0000
  • f6b447f6e7 fix for "NameError: global name 'webFileStreamUpload' is not defined" Miroslav Stampar 2010-01-28 08:54:47 +0000
  • a20bbc3974 Removed carriage return (\r) from UDFs shared library source code Bernardo Damele 2010-01-28 01:16:01 +0000
  • 645afee359 some changes Miroslav Stampar 2010-01-28 00:25:36 +0000
  • 921e449454 added support for cloaking Churrasco.exe file Miroslav Stampar 2010-01-28 00:07:33 +0000
  • 4559ded6c1 added new line at the end of the file Miroslav Stampar 2010-01-27 17:02:23 +0000
  • f4b8ce5c72 fix for 'No such file or directory' OSError exception Miroslav Stampar 2010-01-27 17:00:54 +0000
  • 00002eeb38 bad grammar fix Miroslav Stampar 2010-01-27 16:05:32 +0000
  • d0acb1c5a3 another fix. hope it works :) Miroslav Stampar 2010-01-27 16:01:50 +0000
  • f8056f4098 quick fix regarding usage of StringIO instead of file stream Miroslav Stampar 2010-01-27 15:44:35 +0000
  • a0eabb6719 Id property set Miroslav Stampar 2010-01-27 14:28:34 +0000
  • 8a8dc73980 more fixes Miroslav Stampar 2010-01-27 14:27:11 +0000
  • 1d15c595a4 minor fix Miroslav Stampar 2010-01-27 14:08:09 +0000
  • e63428207c modified a way to handle shell scripts Miroslav Stampar 2010-01-27 13:59:25 +0000
  • f91687c4f7 removed old plain text shell scripts Miroslav Stampar 2010-01-27 13:58:28 +0000
  • 6966c235a4 removed junk file Miroslav Stampar 2010-01-27 13:57:19 +0000
  • 93b7994c0c added new cloaking functionality for shell scripts Miroslav Stampar 2010-01-27 13:56:26 +0000
  • a78bf9a88b new files Miroslav Stampar 2010-01-27 13:55:13 +0000
  • 6437c16156 run kitrap0d script along with listing Windows Impersonation Tokens via meterpreter's incognito extension when --priv-esc is provided (see #149). Bernardo Damele 2010-01-26 01:14:44 +0000
  • a97e20d8e1 Added proper svn:keywords Bernardo Damele 2010-01-25 11:03:23 +0000
  • 3197fada59 update of IDS checking method Miroslav Stampar 2010-01-25 10:06:52 +0000
  • 952c280083 Added svn keyword Bernardo Damele 2010-01-25 09:21:39 +0000
  • e689c2ec99 another minor fix (svn header comment) Miroslav Stampar 2010-01-25 00:29:19 +0000
  • 44a74ccee8 minor grammar fix Miroslav Stampar 2010-01-25 00:26:51 +0000
  • b183b9cbb4 contains method for detecting if the generated payload is detectable by the PHPIDS filter rules Miroslav Stampar 2010-01-25 00:25:58 +0000
  • a4d8234875 minor update Miroslav Stampar 2010-01-24 14:23:19 +0000
  • 98205cc488 another fix for Bug #148 Miroslav Stampar 2010-01-23 23:29:34 +0000
  • 39652bfbf4 update regarding Unicode char logging (Bug #148) Miroslav Stampar 2010-01-23 15:36:55 +0000
  • 97840535c6 fix for situations where proxy is set in environment, but the user tries to test something on localhost Miroslav Stampar 2010-01-19 13:47:35 +0000
  • 49146e573a Added sys_fileread() for PostgreSQL --read-file binary Bernardo Damele 2010-01-19 13:37:04 +0000
  • 574880ba73 Warn user of HTTP error codes in HTTP responses Bernardo Damele 2010-01-19 10:27:54 +0000
  • b4ce8fe361 Updated ChangeLog file Bernardo Damele 2010-01-18 15:43:06 +0000
  • e4bd0eb92d Updated MSSQL xml signatures file Bernardo Damele 2010-01-18 15:24:59 +0000
  • 5c58747740 More tweaking on --update Bernardo Damele 2010-01-18 15:20:50 +0000
  • 051db588a5 Minor tweaking to --update Bernardo Damele 2010-01-18 14:59:24 +0000
  • 44adbc5776 changes regarding Feature #125 Miroslav Stampar 2010-01-18 14:05:23 +0000
  • 2825ab5e4e Major bug fix in url-encoding Bernardo Damele 2010-01-16 21:56:40 +0000
  • c18a5cb92f Fixed a minor bug when displaying requested page in -v >= 3 Bernardo Damele 2010-01-16 21:47:52 +0000
  • f337cd6e0a Minor speedup to check if sqlmap's UDF have already been created Bernardo Damele 2010-01-16 21:46:35 +0000
  • 6d697d60b2 Minor adjustment Bernardo Damele 2010-01-15 18:00:15 +0000
  • 4ce3abc56d Minor adjustments Bernardo Damele 2010-01-15 17:42:46 +0000
  • 1a764e1f08 minor commit Miroslav Stampar 2010-01-15 16:10:21 +0000
  • 5f171340f5 introduced safe string formatting Miroslav Stampar 2010-01-15 16:06:59 +0000
  • dcf0b2a3c1 minor update Miroslav Stampar 2010-01-15 11:45:48 +0000
  • f5c422efb4 updated and renamed sanitizeCookie to urlEncodeCookieValues because of it's different nature than before Miroslav Stampar 2010-01-15 11:44:05 +0000
  • 505647b00f Minor bug fix to --cookie-urlencode Bernardo Damele 2010-01-15 11:24:30 +0000
  • c4215ce8d2 Minor code refactoring Bernardo Damele 2010-01-14 20:42:45 +0000
  • 26c7b74e65 changes regarding Data (GET/POST/Cookie) encoding (Bug #129) Miroslav Stampar 2010-01-14 18:05:03 +0000
  • 1d968f51e9 More code refactoring Bernardo Damele 2010-01-14 15:11:32 +0000
  • c9863bc1d2 Minor code refactoring Bernardo Damele 2010-01-14 14:33:08 +0000
  • 070ccc30e9 Added automatic support in --os-pwn to use the web uploader/backdoor to upload and execute the Metasploit payload stager when stacked queries SQL injection is not supported, for instance on MySQL/PHP and MySQL/ASP. Updated ChangeLog. Major code refactoring. Bernardo Damele 2010-01-14 14:03:16 +0000
  • 1febdcac9b Added support for takeover functionalities on PgSQL 8.4 running on Linux too. Recompilation of MySQL shared object with MySQL 5.1 development libraries on Debian 5.3. Tweaked the UDF compilation/installation files for both MySQL and PgSQL. Bernardo Damele 2010-01-14 10:50:03 +0000
  • d4d26b59eb Merged UDF Linux and Windows development environments Bernardo Damele 2010-01-14 01:51:20 +0000
  • 746cbdba96 Added support for takeover functionalities on PgSQL 8.4 running on Windows Bernardo Damele 2010-01-14 01:40:11 +0000
  • 1100b37feb Minor adjustments to UDF source code and file system structure Bernardo Damele 2010-01-14 00:46:48 +0000
  • 2915b5d7e9 Partial cleanup of UDF source code path Bernardo Damele 2010-01-13 23:18:17 +0000
  • 625cc5cc0d Slight update to the shared libraries (UDF dlls). Bernardo Damele 2010-01-13 21:28:05 +0000
  • b4ddfe8333 Minor bug fixed (variable undeclared) Bernardo Damele 2010-01-13 21:26:59 +0000
  • 50bbb0cf8a Deprecate sqlmap update code, will use pysvn to update from latest development version from subversion repository. Bernardo Damele 2010-01-13 14:52:23 +0000
  • 9c9988c375 Updated MSSQL xml signatures file Bernardo Damele 2010-01-13 14:50:13 +0000
  • 055b14a11a Updated Changelog Bernardo Damele 2010-01-13 12:14:29 +0000
  • 0ad43952bd Minor bug fix Bernardo Damele 2010-01-12 23:56:43 +0000
  • f9f418b479 minor modification of a sample in sqlmap.conf Miroslav Stampar 2010-01-12 14:24:58 +0000