Commit Graph

  • 401763b6f8 minor fix (it has to be level 1 array like it was with the previous re.findall mechanism) Miroslav Stampar 2012-03-19 12:00:22 +0000
  • 72c5b034bf minor update Miroslav Stampar 2012-03-19 11:50:38 +0000
  • cb8caf7e0f i am not very bright today :) Miroslav Stampar 2012-03-19 11:23:23 +0000
  • d5915e5d44 one other fix Miroslav Stampar 2012-03-19 11:19:26 +0000
  • 7abfa2e6d4 minor fix Miroslav Stampar 2012-03-19 11:18:00 +0000
  • cce5c3c009 minor changes for version numbers Miroslav Stampar 2012-03-19 11:07:03 +0000
  • 037db9b3b8 minor removal of older stuff Miroslav Stampar 2012-03-19 09:38:27 +0000
  • da7f4eeffd removing left over Miroslav Stampar 2012-03-18 17:33:14 +0000
  • 0fc4288a7c modifying redirection code for only two choices Miroslav Stampar 2012-03-18 17:27:08 +0000
  • c03d0e24fb it must stay as is Bernardo Damele 2012-03-16 17:42:00 +0000
  • 3505503a08 no need to return here Bernardo Damele 2012-03-16 17:30:16 +0000
  • 942d9e4fa8 code cleanup Bernardo Damele 2012-03-16 17:27:24 +0000
  • a1c943fc79 Major bug fix to comparison algorithm with OR based boolean-based injections Bernardo Damele 2012-03-16 17:22:55 +0000
  • d66056fe39 one more related commit Miroslav Stampar 2012-03-16 13:16:53 +0000
  • ac02a2d92c minor fix Miroslav Stampar 2012-03-16 13:14:14 +0000
  • cbdcbdd786 minor minor update Miroslav Stampar 2012-03-16 11:18:18 +0000
  • b130a9e14e minor fix (writing to HashDB on any interrupt) Miroslav Stampar 2012-03-16 10:15:43 +0000
  • 577caac4de putting kb.negativeLogic setting to the safe place Miroslav Stampar 2012-03-16 09:17:11 +0000
  • 209e795369 minor just in case update Miroslav Stampar 2012-03-16 09:02:17 +0000
  • adb5fff6b2 one more update related to the redirection mechanism Miroslav Stampar 2012-03-15 20:17:40 +0000
  • 7d313ac911 few more fixes for proper redirecting mechanism Miroslav Stampar 2012-03-15 19:47:59 +0000
  • 48e8c978fb Minor fix, way more to do for --search -C for MSSQL Bernardo Damele 2012-03-15 17:55:49 +0000
  • 86c4650058 Minor bug fix - revert Bernardo Damele 2012-03-15 17:12:24 +0000
  • cc15373769 More explicit function name also getRatioValue parameter has nothing to do with comparison at this stage as far as I can see (that might have fixed another "bug", to be checked later) Bernardo Damele 2012-03-15 16:29:28 +0000
  • 4520744b4d second step toward negative logic support (ported to detection phase too) - works well with --string, --regexp and --code now Bernardo Damele 2012-03-15 16:25:26 +0000
  • 0013b0970f Minor layout adjustments - foundDb is misleading at that stage Bernardo Damele 2012-03-15 16:07:16 +0000
  • ddd92476a8 minor fix Miroslav Stampar 2012-03-15 15:58:25 +0000
  • 19beb912fa first step toward negative logic support Miroslav Stampar 2012-03-15 15:52:12 +0000
  • 8dd570057b minor fix (double traffic log for -t in case of HTTP error) Miroslav Stampar 2012-03-15 14:51:16 +0000
  • f7df755f37 minor update Miroslav Stampar 2012-03-15 12:55:22 +0000
  • 3d39c6cb3b some fixes here and there Miroslav Stampar 2012-03-15 12:14:50 +0000
  • 3d9b1599d1 minor update Miroslav Stampar 2012-03-15 11:45:32 +0000
  • 91f1d6141f minor fix Miroslav Stampar 2012-03-15 11:24:55 +0000
  • a8c9a47092 redirect logic rewritten from scratch Miroslav Stampar 2012-03-15 11:10:58 +0000
  • 84479eebe9 minor fix Miroslav Stampar 2012-03-15 08:55:42 +0000
  • 890bf708bc Minor fixes to make --os-* switch work again against MySQL/Windows/ASP.NET (where stacked queries are supported) Bernardo Damele 2012-03-15 00:19:57 +0000
  • 8cf5d260fd Application Data is not a temporary directory writable by everybody Miroslav Stampar 2012-03-14 23:44:29 +0000
  • 1e71b24dca More info messages to prove xp_cmdshell (and temporary directory choosen) worked Bernardo Damele 2012-03-14 22:41:53 +0000
  • c735d846ee The default temporary directory as to stay as is, do not touch this code snippet anymore please Bernardo Damele 2012-03-14 22:39:46 +0000
  • 52a8b25ff4 minor fix Miroslav Stampar 2012-03-14 14:31:41 +0000
  • ca0d068575 distinguishing NULL from BLANK Miroslav Stampar 2012-03-14 13:52:23 +0000
  • e38b59a2ae minor update Miroslav Stampar 2012-03-14 13:16:49 +0000
  • cee9ff7885 proper parsing of content in partial union technique Miroslav Stampar 2012-03-14 11:23:30 +0000
  • 61ad3b999a fix for a crash with partial union and --hex Miroslav Stampar 2012-03-14 10:31:24 +0000
  • a7fbc55748 grammar fix Miroslav Stampar 2012-03-13 22:03:23 +0000
  • edfcddd3c3 minor fix for logging only cookies used by request (e.g. --load-cookies case) Miroslav Stampar 2012-03-13 10:58:15 +0000
  • 34b0935cb3 refactoring "echo 1" quick test for xp_cmdshell console output Miroslav Stampar 2012-03-13 10:36:49 +0000
  • e827f41cdb using pickle HIGHEST_PROTOCOL just in case Miroslav Stampar 2012-03-13 09:35:37 +0000
  • e6c610abab minor fix Miroslav Stampar 2012-03-13 09:14:56 +0000
  • cda8815634 introducing safe deprecation mechanism for HashDB versioning Miroslav Stampar 2012-03-12 22:55:57 +0000
  • 48bcde478e more general update Miroslav Stampar 2012-03-12 15:29:55 +0000
  • 1d0c8a7f44 minor update Miroslav Stampar 2012-03-12 15:19:02 +0000
  • 6ed1b04bbe minor update Miroslav Stampar 2012-03-12 13:27:07 +0000
  • 48592f2515 minor adjustments Bernardo Damele 2012-03-09 18:34:18 +0000
  • be9b103b51 minor bug fix Bernardo Damele 2012-03-09 18:02:50 +0000
  • 012fc21b49 Improvements to column(s) search: now it's possible to search column(s) in provided table(s) across all databases, search column(s) across all tables in provided database(s) or let sqlmap alone identify the databases' tables - this is now implemented for error-based, union query and direct connection. Work is still required for boolean-based and time-based. Adapted the queries.xml file accordingly Bernardo Damele 2012-03-09 17:47:50 +0000
  • c878dd3e5a doing a dummy test for --os-shell in case of xp_cmdshell Miroslav Stampar 2012-03-09 14:21:41 +0000
  • 4ac2611a56 Added another tamper script Bernardo Damele 2012-03-09 12:09:19 +0000
  • d9e499af9f Set Id property Bernardo Damele 2012-03-09 12:05:21 +0000
  • a0b46963cb minor fix for some special "unusable" cases (seen on Access/ODBC/Linux setup) Miroslav Stampar 2012-03-09 10:28:19 +0000
  • 7330dff255 Minor bug fix for --search -C so that now if not columns are found (with criteria specified, e.g. -D testdb -T testtable), it won't ask to dump for the entries Bernardo Damele 2012-03-08 16:57:53 +0000
  • e678219a8c minor update Miroslav Stampar 2012-03-08 15:51:30 +0000
  • ae87df5670 leftover Bernardo Damele 2012-03-08 15:45:33 +0000
  • 5a83f1c5f7 minor update Miroslav Stampar 2012-03-08 15:43:22 +0000
  • 4bc6f3f6c9 Minor bug fix so that --search -T tablename -D db1,db2 now correctly forges the query concatenating db1 and db2 with a OR, not an AND anymore Bernardo Damele 2012-03-08 15:32:05 +0000
  • 68b9d48d0a minor update Miroslav Stampar 2012-03-08 15:30:23 +0000
  • 2ab80bfb2c minor bug fix Miroslav Stampar 2012-03-08 15:24:05 +0000
  • c79807f5fb Minor layout adjustments Bernardo Damele 2012-03-08 15:11:24 +0000
  • 775e424bf2 bug fix for using --no-cast and --hex switches together Miroslav Stampar 2012-03-08 15:04:52 +0000
  • 11c7cc5224 minor temporary fix Miroslav Stampar 2012-03-08 11:08:43 +0000
  • 98a3e43f53 bug fix for writing raw pickled data into SQLite HashDB Miroslav Stampar 2012-03-08 10:57:47 +0000
  • cd28eb6544 minor update regarding --load-cookies Miroslav Stampar 2012-03-08 10:19:34 +0000
  • 2c87d061e9 minor update Miroslav Stampar 2012-03-08 10:03:59 +0000
  • 9ca8bc4d51 minor bug fix Miroslav Stampar 2012-03-08 09:52:33 +0000
  • b4cf8b05b3 added switch --load-cookies Miroslav Stampar 2012-03-07 14:48:45 +0000
  • 4cfea96471 minor update Miroslav Stampar 2012-03-05 09:56:48 +0000
  • 0ead1fd87e minor update Miroslav Stampar 2012-03-05 09:42:52 +0000
  • ac5a752b12 Oracle's XMLType doesn't like '#' char too Miroslav Stampar 2012-03-01 11:59:37 +0000
  • 761ec7529a minor appereance fix Miroslav Stampar 2012-03-01 11:52:30 +0000
  • f4e410db16 minor fix Miroslav Stampar 2012-03-01 10:17:39 +0000
  • 1ec56f93ec minor update Miroslav Stampar 2012-03-01 10:10:19 +0000
  • 2d3c12d2d0 shorter single line info Miroslav Stampar 2012-03-01 09:10:24 +0000
  • 37db27b720 turning back on automatic adjusting of delays in time based queries Miroslav Stampar 2012-02-29 15:51:23 +0000
  • 0205d96d7b minor fix Miroslav Stampar 2012-02-29 15:38:01 +0000
  • 1bdc07c279 minor update Miroslav Stampar 2012-02-29 15:02:24 +0000
  • 8b9c5c66cc code refactoring regarding charsetType inside inference/bisection Miroslav Stampar 2012-02-29 14:36:23 +0000
  • f6f98f1b41 minor improvement Miroslav Stampar 2012-02-29 14:19:59 +0000
  • 10dd9096f7 one more just in case fix for safeSQLIdentificator naming on MSSQL --tables Miroslav Stampar 2012-02-29 14:05:53 +0000
  • d06182347f fixing few potential problems Miroslav Stampar 2012-02-29 13:56:40 +0000
  • c39d85420a removing PGP Key ID from my info too (used only few times in couple of years) Miroslav Stampar 2012-02-29 09:56:41 +0000
  • f142c0f782 minor update Miroslav Stampar 2012-02-28 14:04:13 +0000
  • 22b3fa0749 minor update Miroslav Stampar 2012-02-27 15:28:36 +0000
  • a9bf0297f6 moving injection data to HashDB Miroslav Stampar 2012-02-27 13:44:07 +0000
  • 68e08d2749 minor fix for not displaying 'None' but None in enumeration when data unavailable Miroslav Stampar 2012-02-27 13:15:10 +0000
  • a424de3102 minor fix Miroslav Stampar 2012-02-27 12:55:28 +0000
  • 1e82405bb9 HashDB is now supported in -d too Miroslav Stampar 2012-02-27 12:14:01 +0000
  • 3909658fc2 few minor just in case updates Miroslav Stampar 2012-02-27 11:15:53 +0000
  • 85125018a1 minor bug fix Miroslav Stampar 2012-02-25 22:54:32 +0000
  • 5d307cf886 minor update Miroslav Stampar 2012-02-25 10:54:39 +0000
  • 06ab3fa134 minor update Miroslav Stampar 2012-02-25 10:53:38 +0000