Commit Graph

  • 6369a38ebc Adding support for JSON-like data with single quote Miroslav Stampar 2014-02-26 08:56:17 +0100
  • 465f968be6 Minor cosmetic update Miroslav Stampar 2014-02-26 08:41:23 +0100
  • edc8ef9d5b Patch for an Issue #611 (original page used in case of tamper functions was wrong - e.g. if --tamper=base64encode was used) Miroslav Stampar 2014-02-25 13:48:34 +0100
  • 2a423d61ef Raising number of requests for false positive testing in case of higher levels Miroslav Stampar 2014-02-23 19:40:01 +0100
  • d405fc1157 Minor update (for the consistency sake) Miroslav Stampar 2014-02-16 22:04:12 +0100
  • 58eac364a2 Bug fix Miroslav Stampar 2014-02-16 21:57:14 +0100
  • dfa727cbc5 Fix for a same bug mentioned in last commit Miroslav Stampar 2014-02-16 21:47:14 +0100
  • 43df4efd11 Bug fix (bad idea is to do os.path.join on web URLs - especially on Windows OS) Miroslav Stampar 2014-02-16 21:44:57 +0100
  • d05bfdd7dd Implementing option '--where' (Issue #605) Miroslav Stampar 2014-02-11 16:20:45 +0100
  • be6767b3b0 minor fix for command execution via web shell Bernardo Damele 2014-02-10 09:59:57 +0000
  • fe0ff6e679 Changing 'is injectable' to 'seems to be injectable' for boolean and time-based blind injection cases - for false positive cases Miroslav Stampar 2014-02-09 17:50:16 +0100
  • 8521265526 Minor fix Miroslav Stampar 2014-02-07 14:40:43 +0100
  • 8fa452dc9f Updated History (markdown) Bernardo Damele A. G. 2014-02-05 09:07:21 -0800
  • de8cb15350 Fix for an Issue #601 Miroslav Stampar 2014-02-05 15:11:39 +0100
  • b83d531ab3 Minor fix (Reference: https://en.wikipedia.org/wiki/Internet_Information_Services) Miroslav Stampar 2014-02-05 08:32:55 +0100
  • f28b8dbda8 Minor update Miroslav Stampar 2014-02-01 22:24:56 +0100
  • 534c2ee0e6 Minor update Miroslav Stampar 2014-02-01 22:12:00 +0100
  • 0e44132778 Removing unused imports Miroslav Stampar 2014-02-01 21:49:12 +0100
  • f97fcb7bb3 Adding a switch --invalid-string Miroslav Stampar 2014-01-23 21:56:06 +0100
  • f88f6dcd7e Changing --invalid-bignum from float producing to int producing Miroslav Stampar 2014-01-23 09:07:25 +0100
  • fc02badf40 Minor update Miroslav Stampar 2014-01-23 08:33:21 +0100
  • ab36e5a2f0 Fix for an Issue #597 Miroslav Stampar 2014-01-15 10:29:53 +0100
  • bc29bf6481 removed comments Bernardo Damele 2014-01-13 23:57:49 +0000
  • 1505f1dc74 removed useless sink Bernardo Damele 2014-01-13 23:55:32 +0000
  • 124ebefc7f code cleanup Bernardo Damele 2014-01-13 23:48:15 +0000
  • 4e8ab48145 fixed match Bernardo Damele 2014-01-13 23:48:00 +0000
  • b86353b485 minor fix to DB2 test case Bernardo Damele 2014-01-13 23:34:25 +0000
  • 85f60d0c09 leftovers Bernardo Damele 2014-01-13 17:41:33 +0000
  • 536b44a429 adapted Bernardo Damele 2014-01-13 17:38:04 +0000
  • 3c79d66569 fixed stderr Bernardo Damele 2014-01-13 17:34:38 +0000
  • 43a4e85749 updated copyright Bernardo Damele 2014-01-13 17:24:49 +0000
  • d546fc5ad5 slight update to regression test regexp Bernardo Damele 2014-01-13 17:24:09 +0000
  • 9a1be29b45 updated test cases for regression test Bernardo Damele 2014-01-13 17:12:59 +0000
  • dfa9076a70 fixed and improved web shell upload in MySQL (it was actually broken since fc57b7565d) Bernardo Damele 2014-01-13 17:12:37 +0000
  • 6863436d4e Implementation for an Issue #596 Miroslav Stampar 2014-01-13 10:05:49 +0100
  • b4139f5b82 added takeover shared object for PgSQL 9.1 Linux 32-bit - issue #20 Bernardo Damele 2014-01-10 18:16:25 +0000
  • 4975aafa65 updated live tests Bernardo Damele 2014-01-10 17:38:04 +0000
  • 148767941b new host Bernardo Damele 2014-01-10 17:23:27 +0000
  • d9e00adfae minor fix Bernardo Damele 2014-01-10 17:23:16 +0000
  • 36f3ab5798 Minor bug fix (for cases when race between thread and main thread is causing server._running to not be set to True) Miroslav Stampar 2014-01-09 15:46:55 +0100
  • cb1f17cb04 Proper patch for an Issue #591 Miroslav Stampar 2014-01-02 12:15:56 +0100
  • 5437f8bf36 Fix for an Issue #85 Miroslav Stampar 2014-01-02 12:09:58 +0100
  • 4de83daf03 Minor style update Miroslav Stampar 2014-01-02 11:06:19 +0100
  • e0143e397a Consistency fix (down below we use direct SQL) Miroslav Stampar 2014-01-02 10:59:53 +0100
  • 0b4fcb6845 Fix for an Issue #591 Miroslav Stampar 2014-01-02 10:55:40 +0100
  • 854a55166c Fix for an Issue #588 Miroslav Stampar 2014-01-02 10:29:10 +0100
  • 9b4b070ecf Minor cosmetics Miroslav Stampar 2014-01-02 10:05:58 +0100
  • 192a911b76 Patch for an Issue #28 Miroslav Stampar 2013-12-29 16:16:50 +0100
  • 41d6c1af82 Patch for an Issue #589 Miroslav Stampar 2013-12-28 13:47:40 +0100
  • 6c80f2903b Patch for an Issue #564 Miroslav Stampar 2013-12-27 11:02:59 +0100
  • 178056968f Cleaning a leftover (deleted) made for Issue #564 Miroslav Stampar 2013-12-27 10:49:15 +0100
  • cadbddd607 Adding a boundary proposed in Issue #564 Miroslav Stampar 2013-12-27 10:46:18 +0100
  • 7718edac9b Fix for an Issue #570 Miroslav Stampar 2013-12-27 09:40:33 +0100
  • 02de2aee6d Patch for an Issue #582 Miroslav Stampar 2013-12-26 22:27:04 +0100
  • ab64d385d6 Bug fix (stacked queries as in PgSQL and MsSQL DNS tunneling queries MUST end with the comment - not the recognized underlying technique's suffix) Miroslav Stampar 2013-12-25 22:18:57 +0100
  • 2c2667b2be Minor patch for an Issue #575 Miroslav Stampar 2013-12-18 00:56:11 +0100
  • fd6dcd8bf5 Merge pull request #583 from mattoufoutu/api Miroslav Stampar 2013-12-17 14:10:19 -0800
  • 9ead80d707 Minor patch for Issue #585 Miroslav Stampar 2013-12-17 09:39:43 +0100
  • f18abb1e9c Minor update (proxy can be also a https one (e.g. Burp for HTTPS targets) Miroslav Stampar 2013-12-17 09:30:51 +0100
  • 7d8eb148ce Patch for an Issue #565 (DuckDuckGo doesn't like identity encoding) Miroslav Stampar 2013-12-17 09:30:04 +0100
  • 4819e19200 Patch for an Issue #584 Miroslav Stampar 2013-12-16 22:00:47 +0100
  • 4c9456dd72 moar logging! Mathieu Deous 2013-12-15 16:59:47 +0100
  • 438ad73016 avoid names shadowing Mathieu Deous 2013-12-15 09:22:01 +0100
  • eda9a3da67 all instance attributes should be defined in constructor Mathieu Deous 2013-12-15 09:16:38 +0100
  • 3effaee2a1 avoid using global variables, use a "store" class Mathieu Deous 2013-12-15 00:19:58 +0100
  • c70f2a4e6d unused imports Mathieu Deous 2013-12-15 00:00:08 +0100
  • aa02019638 return file content in a json message when calling download endpoint Mathieu Deous 2013-12-14 16:33:17 +0100
  • c87ad1bab5 make returned values more coherent Mathieu Deous 2013-12-14 16:22:30 +0100
  • 72137e85f9 do not reset options when firing a scan Mathieu Deous 2013-12-14 15:59:47 +0100
  • af7ad31182 fix commit method usage (belongs to connection, not cursor) Mathieu Deous 2013-12-14 15:58:09 +0100
  • c5a3f54b89 remove unused imports Mathieu Deous 2013-12-14 15:47:26 +0100
  • 8a946509b9 PEP8 Mathieu Deous 2013-12-14 15:44:10 +0100
  • 5b2ded0b18 Fix for an Issue #577 Miroslav Stampar 2013-12-13 21:00:26 +0100
  • 437278e32d Fix for an Issue #580 Miroslav Stampar 2013-12-13 19:48:05 +0100
  • 93628cdd62 Merge pull request #578 from mattoufoutu/master Miroslav Stampar 2013-12-09 04:52:34 -0800
  • c3dd6e1e32 api's get_option function doesn't lookup the right object Mathieu Deous 2013-12-08 17:46:02 +0100
  • a06a6de193 minor bug fix Bernardo Damele 2013-12-06 13:26:34 +0000
  • b7244a07cb Changing testing payload for MsSQL (BINARY_CHECKSUM seems to be blocked in some cases) Miroslav Stampar 2013-12-04 11:32:42 +0100
  • b0ca34ff27 Bug fix (payload character '=' was not being url-encoded in custom (user) post cases - when posthint was None) Miroslav Stampar 2013-12-04 10:09:54 +0100
  • bf3fbb0ae0 Ignore Google analytics cookies Miroslav Stampar 2013-12-04 09:56:37 +0100
  • dd2ddec79a Minor fix (better extraction of original value in case of replacement and custom POST injection mark) Miroslav Stampar 2013-12-03 13:37:04 +0100
  • 59d667d94c Minor update Miroslav Stampar 2013-12-01 22:25:12 +0100
  • 663b1e711b Bug fix Miroslav Stampar 2013-12-01 21:22:29 +0100
  • 07bd22fa80 Minor fix Miroslav Stampar 2013-12-01 21:03:30 +0100
  • 7054586e8a Update for an Issue #565 (more work TBD - DuckDuckGo has some kind of IP blocking mechanism) Miroslav Stampar 2013-11-25 20:57:07 +0100
  • 24e67289c8 Bug fix Miroslav Stampar 2013-11-25 11:57:20 +0100
  • cda27ec20b Patch for an Issue #563 Miroslav Stampar 2013-11-24 15:01:26 +0100
  • 59b6791faa minor improvement Bernardo Damele 2013-11-19 00:24:47 +0000
  • c37ad88283 minor bug fix Bernardo Damele 2013-11-13 14:34:19 +0000
  • 3c67ba08c5 Minor fix Miroslav Stampar 2013-11-12 14:53:05 +0100
  • 354aaeae5b Removing unused imports Miroslav Stampar 2013-11-12 14:11:07 +0100
  • d84ddf23bd Replacing os.sep constructs with os.path.join Miroslav Stampar 2013-11-12 14:08:41 +0100
  • 2f1607b4d5 Minor fix for dumping non-alphanumeric database names Miroslav Stampar 2013-11-12 13:13:47 +0100
  • abd76081e1 Adding a new WAF script (varnish.py) Miroslav Stampar 2013-11-11 09:25:42 +0100
  • 3ff01f5777 Adding new tamper script Miroslav Stampar 2013-11-09 00:23:34 +0100
  • 0a4512e9ae Implementation for an Issue #557 Miroslav Stampar 2013-11-08 09:23:38 +0100
  • ae4cd2ebed Minor update Miroslav Stampar 2013-11-07 08:29:32 +0100
  • 48bd2e75e9 Minor patch Miroslav Stampar 2013-10-28 13:59:38 +0100
  • 7ed05f01b3 Minor update Miroslav Stampar 2013-10-27 00:24:57 +0200
  • fabbe63f00 Proper fix for re.sub() call with repl value containing backslash Miroslav Stampar 2013-10-23 18:07:38 +0200