Commit Graph

  • 3f6bc1f3c2 minor fix Miroslav Stampar 2012-05-24 18:05:33 +0000
  • 1e18168cc8 fix for one silent bug and small language update Miroslav Stampar 2012-05-23 16:35:40 +0000
  • 2538e2d5b4 fixing an issue with --file-read and ROW() MySQL payload (it's internal caching mechanism prevents error message if FROM part is not unique enough dumping only partial file content); minor refactoring Miroslav Stampar 2012-05-22 09:33:22 +0000
  • 2c057d5b3d minor style update Miroslav Stampar 2012-05-21 22:40:52 +0000
  • 3a9e266d78 adding revisited wildcard LIKE payloads Miroslav Stampar 2012-05-21 21:49:54 +0000
  • 602369c762 reverting last changes on boundaries Miroslav Stampar 2012-05-21 09:20:46 +0000
  • 588d829be6 update of doc/THANKS Miroslav Stampar 2012-05-21 08:34:12 +0000
  • 1500b3fccd adding a new payload boundaries by smcintyre@securestate.com Miroslav Stampar 2012-05-21 08:31:37 +0000
  • 0e8d8577a7 adding a DB2 patch from smcintyre@securestate.com Miroslav Stampar 2012-05-21 08:26:19 +0000
  • 079e0e1434 minor bug fix Miroslav Stampar 2012-05-18 08:51:50 +0000
  • bbfa4b6d5d minor update Miroslav Stampar 2012-05-14 14:38:16 +0000
  • 333f8057a5 minor fix (when redirected path has non-ASCII char and conf.url is unicode) and bits along with pieces Miroslav Stampar 2012-05-14 14:06:43 +0000
  • 595f69fa2c minor language update Miroslav Stampar 2012-05-10 18:30:25 +0000
  • 35f400b45b minor language upgrade Miroslav Stampar 2012-05-10 18:25:12 +0000
  • 80aedbe284 adding a warning about --tor switch Miroslav Stampar 2012-05-10 18:17:32 +0000
  • b81fe42d4b turning off null connection on -o when --tor used (not compatible) Miroslav Stampar 2012-05-10 17:50:54 +0000
  • efdd86ddcc minor just in case patch Miroslav Stampar 2012-05-10 14:22:34 +0000
  • 6367f59b98 minor code refactoring Miroslav Stampar 2012-05-10 14:15:17 +0000
  • 12d32f58f2 fix for that SOAP reported bug Miroslav Stampar 2012-05-10 13:39:54 +0000
  • 1418ae9767 little refactoring of parseUnionPage together with a patch for some special case Miroslav Stampar 2012-05-09 18:47:40 +0000
  • 7fb1f3fc70 minor renaming Miroslav Stampar 2012-05-09 18:26:02 +0000
  • 11d9859199 making nice code Miroslav Stampar 2012-05-09 18:25:04 +0000
  • b0a8238774 minor fixes Miroslav Stampar 2012-05-09 14:58:16 +0000
  • 9fa3619262 minor fix Miroslav Stampar 2012-05-09 14:00:07 +0000
  • 56a3431be6 minor update for empty tables (skipping other techniques) Miroslav Stampar 2012-05-09 10:34:21 +0000
  • 6177317a17 minor update Miroslav Stampar 2012-05-09 10:06:23 +0000
  • 37f2709197 making a generic solution for all "Generic comment"/MsAccess cases (it's the only DBMS which doesn't accept --, hence replacing generic comment with %00 for it) Miroslav Stampar 2012-05-09 09:08:23 +0000
  • fdf61015ad minor patch Miroslav Stampar 2012-05-09 08:41:05 +0000
  • e419177871 minor update Miroslav Stampar 2012-05-08 17:28:19 +0000
  • deec97dfe3 adding Frontbase to error message regexes Miroslav Stampar 2012-05-08 17:02:58 +0000
  • eccd4da00f minor fix Miroslav Stampar 2012-05-08 15:03:33 +0000
  • 938d9ff23e doing all the work for the users so they wouldn't strain their little hands Miroslav Stampar 2012-05-08 15:00:23 +0000
  • 524dd75ff2 that query variable hasn't been used anywhere (obsolete for some time) Miroslav Stampar 2012-05-08 14:34:40 +0000
  • 6af110d631 avoiding --no-cast/--hex warning message before a DBMS is fingerprinted Miroslav Stampar 2012-05-08 14:06:41 +0000
  • 64c241fe92 limiting original UNION query results to only 1 result (potentially speeding things up in some cases) Miroslav Stampar 2012-05-08 13:45:53 +0000
  • e00f4a8934 minor cosmetics Miroslav Stampar 2012-05-08 10:50:04 +0000
  • a121339395 automatically writing uncracked hashes to a file for eventual further processing Miroslav Stampar 2012-05-08 10:46:05 +0000
  • 80ee687b41 minor beauty patch Miroslav Stampar 2012-05-07 13:51:31 +0000
  • e9f6b00e26 minor fix in a KeepAlive library Miroslav Stampar 2012-05-07 13:36:36 +0000
  • 57234e1ff5 fix for proper (international character) inference on MsAccess Miroslav Stampar 2012-05-03 23:13:48 +0000
  • 96299d3d5d minor refactoring Miroslav Stampar 2012-05-03 22:34:18 +0000
  • cc28f6db6b minor update Miroslav Stampar 2012-05-01 20:43:16 +0000
  • 8013a64f8c minor refactoring Miroslav Stampar 2012-05-01 19:57:30 +0000
  • c71d435d9f making "id"-like columns prioritized for ORDER BY in MySQL Miroslav Stampar 2012-05-01 19:52:02 +0000
  • 17efeaae7f causing too much confusion among dummy users Miroslav Stampar 2012-05-01 09:04:11 +0000
  • 458a73c9b4 few consistency fixes Miroslav Stampar 2012-04-29 23:09:00 +0000
  • 694b14111f skipping suffix if comment is used in agent.suffixQuery (and --suffix not explicitly set) Miroslav Stampar 2012-04-27 13:16:51 +0000
  • c7a606637f switching few readInput defaults for brute forcing when no table/column found Miroslav Stampar 2012-04-27 12:59:22 +0000
  • 1e45ee9ab6 reverting back to smaller UNION ranges as that mechanism for automatic extending was implemented few days ago Miroslav Stampar 2012-04-25 20:37:39 +0000
  • 6f67dc85ee adding --invalid-bignum (Havij like bignum style for invalidating/negating values); renaming --logical-negate to --invalid-logical Miroslav Stampar 2012-04-25 20:29:07 +0000
  • 4da03d898e Added support to create files with a visual basic script - no longer reliant on debug.exe so works on Windows 64-bit too. Fixes #236 Bernardo Damele 2012-04-25 07:40:42 +0000
  • 6116853025 Minor layout adjustments Bernardo Damele 2012-04-24 17:01:24 +0000
  • cec432f94d minor update Miroslav Stampar 2012-04-23 14:43:59 +0000
  • 697768c01a adding --purge-output to be one of mandatory switches Miroslav Stampar 2012-04-23 14:42:24 +0000
  • d57d5e4b2c minor update Miroslav Stampar 2012-04-23 14:33:36 +0000
  • 1eecfb3dce adding new file related to the last commit Miroslav Stampar 2012-04-23 14:25:16 +0000
  • 095b25e1d1 adding option '--purge' Miroslav Stampar 2012-04-23 14:24:23 +0000
  • 3532d23933 automatically extending ranges for UNION tests in case where at least one other injection technique is usable (boundaries has been established) Miroslav Stampar 2012-04-23 13:41:36 +0000
  • eb73cab636 increased UNION test ranges Bernardo Damele 2012-04-23 11:54:52 +0000
  • be2da77bf8 minor update Miroslav Stampar 2012-04-23 10:15:04 +0000
  • 21c6b52198 minor fix Miroslav Stampar 2012-04-23 10:11:00 +0000
  • 775134639d minor update Miroslav Stampar 2012-04-20 20:33:15 +0000
  • 072e08836f Falling back to unionReadFile() when --file-read does not work against MySQL. This happens when the session user does not have INSERT privilege, required to run LOAD DATA INFILE Bernardo Damele 2012-04-19 14:05:45 +0000
  • 2b1b4c0742 minor fix Miroslav Stampar 2012-04-18 10:01:04 +0000
  • 6ebb621228 adding support for (custom) POST injection (marking injection point with '*' in conf.data) Miroslav Stampar 2012-04-17 14:23:00 +0000
  • efd27d7ade minor renaming Miroslav Stampar 2012-04-17 08:41:19 +0000
  • ccd6fb70a8 minor refactoring Miroslav Stampar 2012-04-15 17:17:30 +0000
  • 965c1511a6 adding new tamper script Miroslav Stampar 2012-04-15 17:10:43 +0000
  • 601d118c68 reverting back to UNION ALL scheme (UNION is doing another DISTINCT on data causing problems on some column types) Miroslav Stampar 2012-04-15 16:59:03 +0000
  • 71b0acc16f minor fix (checking for full inband should be done with ORIGINAL - more concise) Miroslav Stampar 2012-04-15 16:43:18 +0000
  • 5772c52f46 minor refactoring/fix (randQuery is just a part (e.g. abc) of phrase (def🔤ghi) - phrase should be searched for, not just randQuery); both phrases should be inside the content for it to be full-inband injectable (...UNION ALL SELECT phrase UNION ALL SELECT phrase2....) Miroslav Stampar 2012-04-15 16:33:47 +0000
  • ae8c70e895 another cosmetics Miroslav Stampar 2012-04-13 15:11:44 +0000
  • d765cdc3a3 minor cosmetics Miroslav Stampar 2012-04-13 15:10:40 +0000
  • 54576ab3a6 making a random choice from candidates Miroslav Stampar 2012-04-13 10:54:30 +0000
  • bbbcc95fe5 use it only if page is stable Miroslav Stampar 2012-04-13 10:19:26 +0000
  • 414c74b8aa new payload Miroslav Stampar 2012-04-13 08:16:33 +0000
  • 052d9455fe warning user in cases of "User xyz already has more than 'max_user_connections' active connections" Miroslav Stampar 2012-04-12 09:44:54 +0000
  • 831f79b851 minor generalization Miroslav Stampar 2012-04-12 09:30:19 +0000
  • c7422546e1 tiny update Miroslav Stampar 2012-04-11 23:01:38 +0000
  • 2bad73a981 minor update Miroslav Stampar 2012-04-11 21:48:44 +0000
  • e195de2093 correcting comment on reflective removal function Miroslav Stampar 2012-04-11 21:41:48 +0000
  • b45ae10da4 minor fixes Miroslav Stampar 2012-04-11 21:36:37 +0000
  • 627bfc589f some more updates in reflective removal mechanism Miroslav Stampar 2012-04-11 21:26:00 +0000
  • 8b130f6497 minor improvement for reflective values (when missing first part of payload like in error reports) Miroslav Stampar 2012-04-11 15:01:28 +0000
  • 01bd5d0ab2 some more updates for reflective mechanism Miroslav Stampar 2012-04-11 10:41:33 +0000
  • 2e92d8636e improvement of reflective mechanism Miroslav Stampar 2012-04-11 08:58:03 +0000
  • 60ca44e0cf minor adjustment Miroslav Stampar 2012-04-11 08:35:09 +0000
  • e33ea7c33a minor fix Miroslav Stampar 2012-04-10 22:29:39 +0000
  • 8541222080 minor update Miroslav Stampar 2012-04-10 22:26:42 +0000
  • 9c2f244d47 minor fix Miroslav Stampar 2012-04-10 22:20:53 +0000
  • a82206cec4 minor cosmetics Miroslav Stampar 2012-04-10 21:57:00 +0000
  • 119eec3598 improving "boolean detection" by automatic recognition of convenient --string candidate Miroslav Stampar 2012-04-10 21:48:34 +0000
  • 698b7a15d9 minor update Miroslav Stampar 2012-04-07 14:14:26 +0000
  • 8c6eb4faa9 adding support for PgSQL DNS data exfiltration Miroslav Stampar 2012-04-07 14:06:11 +0000
  • b2afa87e48 reading page responses in chunks, trimming unnecessary content (especially for large table dumps in full inband cases) Miroslav Stampar 2012-04-06 08:42:36 +0000
  • 2223c884e5 minor refactoring Miroslav Stampar 2012-04-05 12:55:26 +0000
  • 02924eb345 minor update Miroslav Stampar 2012-04-04 23:47:06 +0000
  • e0994947e2 minor update Miroslav Stampar 2012-04-04 23:37:50 +0000
  • b1dd03731a minor cosmetics Miroslav Stampar 2012-04-04 23:34:08 +0000
  • 83387d92bb minor bug fix Miroslav Stampar 2012-04-04 23:32:20 +0000