Commit Graph

  • b85a1fc271 minor fix Miroslav Stampar 2012-06-05 22:55:42 +0000
  • 058a9c59a2 fix for a bug noticed in a multi target run (log files weren't saved properly - removed buffering as it didn't produce any noticeable results) Miroslav Stampar 2012-06-05 22:40:55 +0000
  • f94ebe3107 minor fix (credentials were only set for the first target) Miroslav Stampar 2012-06-04 22:30:12 +0000
  • 738073105e minor updates Miroslav Stampar 2012-06-04 19:52:51 +0000
  • 7b282b1d6c adding support for newer SSL protocols Miroslav Stampar 2012-06-04 19:46:28 +0000
  • 10b0639a96 making a "--exact" switch on demand (choosing exact identifier names by default instead of LIKE) Miroslav Stampar 2012-06-04 09:24:46 +0000
  • 76a4aa19ac some more fine tunning Miroslav Stampar 2012-05-28 19:50:12 +0000
  • 73dba249e8 one more just in case update Miroslav Stampar 2012-05-28 19:34:47 +0000
  • efb406fbfc minor revert Miroslav Stampar 2012-05-28 19:13:50 +0000
  • f7cba8d2cb minor update Miroslav Stampar 2012-05-28 18:05:15 +0000
  • a72cb29c1f taking care of few issues regarding reverse address lookup of localhost/127.0.0.1 at remote DNS server Miroslav Stampar 2012-05-28 16:57:10 +0000
  • 190ae4ca13 no need for conf.timeSec value as inference is always evaluated to False in DNS (large random values used for > ...) Miroslav Stampar 2012-05-28 15:10:17 +0000
  • 89e90c3d84 revert of last commit Miroslav Stampar 2012-05-28 15:01:56 +0000
  • 96c84e6e5b minor update Miroslav Stampar 2012-05-28 15:00:06 +0000
  • a70a647aeb few fixes regarding --dns-domain usage (time-based technique should not be used as a failback because of few things, --time-sec should be put to 0 just in case,...) Miroslav Stampar 2012-05-28 14:51:23 +0000
  • b1d82422a0 changing conf.dnsDomain to conf.dName just because of long text problems in help listing Miroslav Stampar 2012-05-28 14:15:04 +0000
  • d2bbfa4aad minor style update Miroslav Stampar 2012-05-28 14:04:17 +0000
  • 226547b7dc minor fix for --skip-urlencode and custom post Miroslav Stampar 2012-05-28 09:04:25 +0000
  • 75dd1d6a2b minor fix Miroslav Stampar 2012-05-27 21:54:56 +0000
  • e967bbd70f minor patch Miroslav Stampar 2012-05-27 21:44:42 +0000
  • 76eeba10e2 unhiding --dns-domain switch Miroslav Stampar 2012-05-27 18:41:06 +0000
  • fed0212631 now working with recursive queries too Miroslav Stampar 2012-05-27 10:03:02 +0000
  • 71ff081fde minor update Miroslav Stampar 2012-05-27 09:11:19 +0000
  • 09f2144485 full page read is not needed in DNS exfiltration mode Miroslav Stampar 2012-05-26 21:28:43 +0000
  • 4e6fcce9ca minor update Miroslav Stampar 2012-05-26 07:04:32 +0000
  • ce077137c9 minor language update Miroslav Stampar 2012-05-26 07:01:37 +0000
  • d335ec0c34 turning back on time auto-adjustment mechanism (if turned off) after a threshold run of valid chars Miroslav Stampar 2012-05-26 07:00:26 +0000
  • 00d22f013f some consistency in variable naming at the file level Miroslav Stampar 2012-05-25 10:08:55 +0000
  • db526bdbc0 minor update (tainted values are not checked any more in multipleTargets mode) Miroslav Stampar 2012-05-25 09:52:17 +0000
  • dc20bff1d0 minor update Miroslav Stampar 2012-05-25 08:30:24 +0000
  • c394610740 adding switch --skip-urlencode to skip URL encoding of POST data Miroslav Stampar 2012-05-24 23:30:33 +0000
  • 7657bbeaf9 minor update Miroslav Stampar 2012-05-24 22:32:06 +0000
  • 86fdad2bfa minor update Miroslav Stampar 2012-05-24 22:07:50 +0000
  • eed8d7eb5d finalizing support for IPv6 Miroslav Stampar 2012-05-24 21:55:57 +0000
  • b6d37d766a minor update regarding IPv6 support Miroslav Stampar 2012-05-24 21:49:20 +0000
  • 92286104e3 minor just in case update Miroslav Stampar 2012-05-24 21:39:10 +0000
  • 3e9c57d177 minor fix Miroslav Stampar 2012-05-24 21:36:35 +0000
  • be76928293 minor fix Miroslav Stampar 2012-05-24 20:53:01 +0000
  • 3f6bc1f3c2 minor fix Miroslav Stampar 2012-05-24 18:05:33 +0000
  • 1e18168cc8 fix for one silent bug and small language update Miroslav Stampar 2012-05-23 16:35:40 +0000
  • 2538e2d5b4 fixing an issue with --file-read and ROW() MySQL payload (it's internal caching mechanism prevents error message if FROM part is not unique enough dumping only partial file content); minor refactoring Miroslav Stampar 2012-05-22 09:33:22 +0000
  • 2c057d5b3d minor style update Miroslav Stampar 2012-05-21 22:40:52 +0000
  • 3a9e266d78 adding revisited wildcard LIKE payloads Miroslav Stampar 2012-05-21 21:49:54 +0000
  • 602369c762 reverting last changes on boundaries Miroslav Stampar 2012-05-21 09:20:46 +0000
  • 588d829be6 update of doc/THANKS Miroslav Stampar 2012-05-21 08:34:12 +0000
  • 1500b3fccd adding a new payload boundaries by smcintyre@securestate.com Miroslav Stampar 2012-05-21 08:31:37 +0000
  • 0e8d8577a7 adding a DB2 patch from smcintyre@securestate.com Miroslav Stampar 2012-05-21 08:26:19 +0000
  • 079e0e1434 minor bug fix Miroslav Stampar 2012-05-18 08:51:50 +0000
  • bbfa4b6d5d minor update Miroslav Stampar 2012-05-14 14:38:16 +0000
  • 333f8057a5 minor fix (when redirected path has non-ASCII char and conf.url is unicode) and bits along with pieces Miroslav Stampar 2012-05-14 14:06:43 +0000
  • 595f69fa2c minor language update Miroslav Stampar 2012-05-10 18:30:25 +0000
  • 35f400b45b minor language upgrade Miroslav Stampar 2012-05-10 18:25:12 +0000
  • 80aedbe284 adding a warning about --tor switch Miroslav Stampar 2012-05-10 18:17:32 +0000
  • b81fe42d4b turning off null connection on -o when --tor used (not compatible) Miroslav Stampar 2012-05-10 17:50:54 +0000
  • efdd86ddcc minor just in case patch Miroslav Stampar 2012-05-10 14:22:34 +0000
  • 6367f59b98 minor code refactoring Miroslav Stampar 2012-05-10 14:15:17 +0000
  • 12d32f58f2 fix for that SOAP reported bug Miroslav Stampar 2012-05-10 13:39:54 +0000
  • 1418ae9767 little refactoring of parseUnionPage together with a patch for some special case Miroslav Stampar 2012-05-09 18:47:40 +0000
  • 7fb1f3fc70 minor renaming Miroslav Stampar 2012-05-09 18:26:02 +0000
  • 11d9859199 making nice code Miroslav Stampar 2012-05-09 18:25:04 +0000
  • b0a8238774 minor fixes Miroslav Stampar 2012-05-09 14:58:16 +0000
  • 9fa3619262 minor fix Miroslav Stampar 2012-05-09 14:00:07 +0000
  • 56a3431be6 minor update for empty tables (skipping other techniques) Miroslav Stampar 2012-05-09 10:34:21 +0000
  • 6177317a17 minor update Miroslav Stampar 2012-05-09 10:06:23 +0000
  • 37f2709197 making a generic solution for all "Generic comment"/MsAccess cases (it's the only DBMS which doesn't accept --, hence replacing generic comment with %00 for it) Miroslav Stampar 2012-05-09 09:08:23 +0000
  • fdf61015ad minor patch Miroslav Stampar 2012-05-09 08:41:05 +0000
  • e419177871 minor update Miroslav Stampar 2012-05-08 17:28:19 +0000
  • deec97dfe3 adding Frontbase to error message regexes Miroslav Stampar 2012-05-08 17:02:58 +0000
  • eccd4da00f minor fix Miroslav Stampar 2012-05-08 15:03:33 +0000
  • 938d9ff23e doing all the work for the users so they wouldn't strain their little hands Miroslav Stampar 2012-05-08 15:00:23 +0000
  • 524dd75ff2 that query variable hasn't been used anywhere (obsolete for some time) Miroslav Stampar 2012-05-08 14:34:40 +0000
  • 6af110d631 avoiding --no-cast/--hex warning message before a DBMS is fingerprinted Miroslav Stampar 2012-05-08 14:06:41 +0000
  • 64c241fe92 limiting original UNION query results to only 1 result (potentially speeding things up in some cases) Miroslav Stampar 2012-05-08 13:45:53 +0000
  • e00f4a8934 minor cosmetics Miroslav Stampar 2012-05-08 10:50:04 +0000
  • a121339395 automatically writing uncracked hashes to a file for eventual further processing Miroslav Stampar 2012-05-08 10:46:05 +0000
  • 80ee687b41 minor beauty patch Miroslav Stampar 2012-05-07 13:51:31 +0000
  • e9f6b00e26 minor fix in a KeepAlive library Miroslav Stampar 2012-05-07 13:36:36 +0000
  • 57234e1ff5 fix for proper (international character) inference on MsAccess Miroslav Stampar 2012-05-03 23:13:48 +0000
  • 96299d3d5d minor refactoring Miroslav Stampar 2012-05-03 22:34:18 +0000
  • cc28f6db6b minor update Miroslav Stampar 2012-05-01 20:43:16 +0000
  • 8013a64f8c minor refactoring Miroslav Stampar 2012-05-01 19:57:30 +0000
  • c71d435d9f making "id"-like columns prioritized for ORDER BY in MySQL Miroslav Stampar 2012-05-01 19:52:02 +0000
  • 17efeaae7f causing too much confusion among dummy users Miroslav Stampar 2012-05-01 09:04:11 +0000
  • 458a73c9b4 few consistency fixes Miroslav Stampar 2012-04-29 23:09:00 +0000
  • 694b14111f skipping suffix if comment is used in agent.suffixQuery (and --suffix not explicitly set) Miroslav Stampar 2012-04-27 13:16:51 +0000
  • c7a606637f switching few readInput defaults for brute forcing when no table/column found Miroslav Stampar 2012-04-27 12:59:22 +0000
  • 1e45ee9ab6 reverting back to smaller UNION ranges as that mechanism for automatic extending was implemented few days ago Miroslav Stampar 2012-04-25 20:37:39 +0000
  • 6f67dc85ee adding --invalid-bignum (Havij like bignum style for invalidating/negating values); renaming --logical-negate to --invalid-logical Miroslav Stampar 2012-04-25 20:29:07 +0000
  • 4da03d898e Added support to create files with a visual basic script - no longer reliant on debug.exe so works on Windows 64-bit too. Fixes #236 Bernardo Damele 2012-04-25 07:40:42 +0000
  • 6116853025 Minor layout adjustments Bernardo Damele 2012-04-24 17:01:24 +0000
  • cec432f94d minor update Miroslav Stampar 2012-04-23 14:43:59 +0000
  • 697768c01a adding --purge-output to be one of mandatory switches Miroslav Stampar 2012-04-23 14:42:24 +0000
  • d57d5e4b2c minor update Miroslav Stampar 2012-04-23 14:33:36 +0000
  • 1eecfb3dce adding new file related to the last commit Miroslav Stampar 2012-04-23 14:25:16 +0000
  • 095b25e1d1 adding option '--purge' Miroslav Stampar 2012-04-23 14:24:23 +0000
  • 3532d23933 automatically extending ranges for UNION tests in case where at least one other injection technique is usable (boundaries has been established) Miroslav Stampar 2012-04-23 13:41:36 +0000
  • eb73cab636 increased UNION test ranges Bernardo Damele 2012-04-23 11:54:52 +0000
  • be2da77bf8 minor update Miroslav Stampar 2012-04-23 10:15:04 +0000
  • 21c6b52198 minor fix Miroslav Stampar 2012-04-23 10:11:00 +0000
  • 775134639d minor update Miroslav Stampar 2012-04-20 20:33:15 +0000