Commit Graph

  • 89559d1b0a better regex and now after we have that automatic switch off for reflective removal mechanism it's not so important to change it Miroslav Stampar 2011-05-30 20:18:30 +0000
  • 23cec012d1 fix for that unhandled (after program exit) KeyboardInterrupt Miroslav Stampar 2011-05-30 15:13:47 +0000
  • b79dae6e95 minor update Miroslav Stampar 2011-05-30 14:49:03 +0000
  • 20988e58ed warp 5 mr spock :) Miroslav Stampar 2011-05-30 09:46:32 +0000
  • 001cbff2a9 speed up of 2 times for partial union technique Miroslav Stampar 2011-05-30 09:07:48 +0000
  • 97820949f5 minor update Miroslav Stampar 2011-05-30 08:33:01 +0000
  • d5ede6afb4 fix for a dirty reading issue reported by skysbsb@gmail.com (IndexError: list index out of range) Miroslav Stampar 2011-05-30 06:38:44 +0000
  • 23d7820de7 minor update Miroslav Stampar 2011-05-29 23:56:41 +0000
  • 6fd8602f01 minor update Miroslav Stampar 2011-05-29 23:33:34 +0000
  • 86455ceb9c implementation of multithreading for UNION and ERROR techniques Miroslav Stampar 2011-05-29 23:17:50 +0000
  • d51efa679d typo update Miroslav Stampar 2011-05-29 06:26:28 +0000
  • f848cc779e adding legal disclaimer as latest situation (these days news headlines) seems out of control Miroslav Stampar 2011-05-28 18:54:14 +0000
  • a5a70f0895 minor update Miroslav Stampar 2011-05-28 18:21:03 +0000
  • ecbeecdccf minor refactoring Miroslav Stampar 2011-05-28 18:11:56 +0000
  • eb9b84d1da type correction Miroslav Stampar 2011-05-28 17:53:05 +0000
  • 03ef53f00a update regarding mysql function resolution and versionedkeywords Miroslav Stampar 2011-05-28 17:34:43 +0000
  • bfd923fe29 minor update Miroslav Stampar 2011-05-28 16:16:20 +0000
  • 25f3143d92 minor update (to be concise with between) Miroslav Stampar 2011-05-28 16:04:49 +0000
  • b079a543ee minor update Miroslav Stampar 2011-05-28 16:03:36 +0000
  • 7578795c96 adding one more tamper script Miroslav Stampar 2011-05-28 16:02:14 +0000
  • fef9a015da minor update Miroslav Stampar 2011-05-28 15:44:24 +0000
  • 39f131162f adding very useful tampering script Miroslav Stampar 2011-05-28 15:42:47 +0000
  • 95dea1fbf9 sharp tuning UNION tests even more Miroslav Stampar 2011-05-28 08:06:19 +0000
  • 74cc974fa7 cosmetics Miroslav Stampar 2011-05-28 06:44:17 +0000
  • 6e8b689596 removing leftover Miroslav Stampar 2011-05-28 06:40:44 +0000
  • c11ea35d53 adding some user input for "refreshing" cases (like redirect ones) Miroslav Stampar 2011-05-27 22:42:23 +0000
  • cf69809c3c minor update Miroslav Stampar 2011-05-27 16:26:00 +0000
  • 8227298057 user friendliness uber 9000 Miroslav Stampar 2011-05-27 08:30:52 +0000
  • a8b58afdb2 minor update Miroslav Stampar 2011-05-27 08:21:02 +0000
  • 48f52d7697 minor beautification Miroslav Stampar 2011-05-27 08:16:14 +0000
  • 9f6b70f3f9 update Miroslav Stampar 2011-05-26 22:45:33 +0000
  • 61b960f65f minor update related to the last one Miroslav Stampar 2011-05-26 22:05:10 +0000
  • 45caadbd4a important update - finally found what was causing headache for UNION payloads in noticeable number of cases Miroslav Stampar 2011-05-26 21:54:19 +0000
  • 97bd5355dd minor update Miroslav Stampar 2011-05-26 21:18:55 +0000
  • 5d56e89cf5 minor update Miroslav Stampar 2011-05-26 21:08:46 +0000
  • 06108b6da6 minor update related to the last commit Miroslav Stampar 2011-05-26 20:58:24 +0000
  • 4f46a5ab63 minor usability enhancement regarding warning for --text-only switch Miroslav Stampar 2011-05-26 20:48:18 +0000
  • ff030e4d24 minor cleanup of the leftover Miroslav Stampar 2011-05-26 17:37:24 +0000
  • bf2b58ba82 minor update Miroslav Stampar 2011-05-26 15:23:28 +0000
  • 79f0b3a92a adding support for --start and --stop for __pivotDumpTable Miroslav Stampar 2011-05-26 15:16:57 +0000
  • b6fe5b12a4 adding --schema to the wizard/Basic as it looks like a cool thingy to put there Miroslav Stampar 2011-05-26 14:30:05 +0000
  • 46ceb14f37 update of doc/THANKS Miroslav Stampar 2011-05-26 13:49:42 +0000
  • 4f2c999146 fix for a bug reported by mail@8dh.de (UnicodeDecodeError: requestMsg += "\n%s" % requestHeaders) Miroslav Stampar 2011-05-26 13:47:20 +0000
  • 9077eadf23 update of doc/THANKS Miroslav Stampar 2011-05-26 08:22:52 +0000
  • a397baa89a fix for a bug reported by viniciusmaxdaloop@gmail.com and few related patches Miroslav Stampar 2011-05-26 08:17:21 +0000
  • f3ed61af5f bug fix when using inference and kb.pageEncoding is None (like in binary cases) Miroslav Stampar 2011-05-25 21:12:12 +0000
  • 5369657cd5 fix for cases with retrieved binary files (preventing difflib nagging around comparison) Miroslav Stampar 2011-05-25 20:54:30 +0000
  • a1fd2898a0 added friendly tip message for url encoding GET and POST payloads Miroslav Stampar 2011-05-25 11:10:52 +0000
  • 0e480a9921 adding SYS to the ORACLE_SYSTEM_DBS Miroslav Stampar 2011-05-25 10:55:47 +0000
  • 2f456bee75 minor beautification Miroslav Stampar 2011-05-25 08:14:39 +0000
  • 8b7a3c5a6b making it easier for totally dummy users Miroslav Stampar 2011-05-24 17:24:01 +0000
  • bec2c04671 helping dummy users Miroslav Stampar 2011-05-24 17:15:25 +0000
  • a3466ff79c serving everything for the users Miroslav Stampar 2011-05-24 16:34:08 +0000
  • 69eb173eca minor just in case patch Miroslav Stampar 2011-05-24 15:07:37 +0000
  • 0072c3af8e fix for a bug reported by aboynes@gmail.com (for elt in self.a) Miroslav Stampar 2011-05-24 15:03:21 +0000
  • f774d8fea0 proper Tor settings (reverted r3915 and implemented it the right way) Miroslav Stampar 2011-05-24 11:06:58 +0000
  • 0486d1cdaa minor module update Miroslav Stampar 2011-05-24 10:32:21 +0000
  • 915c206e3d minor fix for socks proxy issues Miroslav Stampar 2011-05-24 09:47:10 +0000
  • 0baf931669 real generic comment is "-- " not "--" (MySQL doesn't support "--") Miroslav Stampar 2011-05-24 09:16:21 +0000
  • ad25bcc2be better way for dealing with relative paths Miroslav Stampar 2011-05-24 05:26:51 +0000
  • a536bf210f improved redirection mechanism Miroslav Stampar 2011-05-23 23:20:03 +0000
  • 128a012121 this was causing that --suffix trouble Miroslav Stampar 2011-05-23 19:59:07 +0000
  • bfe8e51b7c minor fix for retrieving stuff like "SELECT * FROM testdb..users" Miroslav Stampar 2011-05-23 19:45:40 +0000
  • 1067d43f14 minor update Miroslav Stampar 2011-05-23 19:16:29 +0000
  • 2b12b18357 incorporating metasploit patch from oliver.kuckertz@mologie.de Miroslav Stampar 2011-05-23 15:27:10 +0000
  • 4542d4535f minor beautification Miroslav Stampar 2011-05-23 14:28:05 +0000
  • 31b48ec11c removing space left Miroslav Stampar 2011-05-23 14:18:33 +0000
  • 0ed03d474f now supporting "blank tables" - schema of the table will be preserved, even if it's empty - especially nice feature for --replicate Miroslav Stampar 2011-05-23 11:09:44 +0000
  • 868fbe370b minor beautification Miroslav Stampar 2011-05-23 10:39:58 +0000
  • 171a4c389b added MySQL >=4.1 <=5.0 error based WHERE/HAVING payload Miroslav Stampar 2011-05-23 06:24:45 +0000
  • fb23beef6f most elegant way i could think of to deal with "collation incompatibilities" issue on some MySQL/UNION cases (affected about 5% of all targets tested) Miroslav Stampar 2011-05-22 19:14:36 +0000
  • 4fdb6ac9b9 adding useful info Miroslav Stampar 2011-05-22 15:30:19 +0000
  • 48c20a62ac minor nag fix Miroslav Stampar 2011-05-22 15:08:55 +0000
  • 40971aca94 fixing nasty bug caused by retrying counter Miroslav Stampar 2011-05-22 10:59:56 +0000
  • 712e238f33 another minor fix Miroslav Stampar 2011-05-22 10:29:25 +0000
  • 2795aeff34 minor fix Miroslav Stampar 2011-05-22 10:27:45 +0000
  • 806e898694 no more CRITICAL drop outs in test mode - lots of reports were related to this Miroslav Stampar 2011-05-22 10:21:49 +0000
  • 7b52bbe3fb reverting that ignoreTimeout for --tables (because of this and that) Miroslav Stampar 2011-05-22 09:59:19 +0000
  • 9b2623514a one bug fix for Host header (value should be without port number); one improvement for --tables - when no tables ask user if he wants to brute force them; one tweak - adding kb.ignoreTimeout for --tables Miroslav Stampar 2011-05-22 09:48:46 +0000
  • 2ea613b170 type correction and adding global flag kb.ignoreTimeout which could be useful Miroslav Stampar 2011-05-22 08:24:13 +0000
  • 27f0e73cc9 refactoring of 'target' flag in connect.py Miroslav Stampar 2011-05-22 07:46:09 +0000
  • a58aaf2e1a better format for results file (easier for sorting when lots of files) Miroslav Stampar 2011-05-22 07:02:36 +0000
  • 25fff8c135 changes in handling --tor (using SOCKS instead of HTTP for handling Tor - more standard way; doesn't require proxy bundle; fixes problems with default proxy ports on Win/Linux) Miroslav Stampar 2011-05-21 11:46:57 +0000
  • 939e6541d0 far safer way for dealing with error-based payloads on MySQL (no timeouts with .CHARACTER_SETS on testing platforms versus when used .TABLES) Miroslav Stampar 2011-05-19 23:36:51 +0000
  • 126cdf9e19 minor info update Miroslav Stampar 2011-05-19 23:28:27 +0000
  • a034462c31 fixing annoying timeouts for basic DBMS check (reference: http://dev.mysql.com/doc/refman/5.0/en/date-and-time-functions.html#function_timestampadd) Miroslav Stampar 2011-05-19 23:03:00 +0000
  • 5a979f7667 minor bug fix for empty colList; also added "do you want to use LIKE" (LIKE is default) question when -C used Miroslav Stampar 2011-05-19 17:35:33 +0000
  • 9e5856caf8 improvement for recognition of scalar vs multiple-row commands Miroslav Stampar 2011-05-19 16:45:05 +0000
  • db72428765 minor update Miroslav Stampar 2011-05-19 15:57:29 +0000
  • f40c6b2ce7 added --cookie for maskSensitiveData too Miroslav Stampar 2011-05-19 15:42:59 +0000
  • bd1b07fbc2 one more parameter replace payload for MySQL and rising level of GENERATE_SERIES for PostgreSQL Miroslav Stampar 2011-05-19 06:32:23 +0000
  • 7f086916c0 decent parameter replace payload for PostgreSQL (GENERATE_SERIES) Miroslav Stampar 2011-05-18 23:40:42 +0000
  • e58d6d2e00 removing (CBRT(LN(0)) because it's nothing special compared to standard 1/0; also, removing parameter replacement with returned value 1 as it doesn't have much sense in comparison to origvalue one (which is far more stable and usable) Miroslav Stampar 2011-05-18 23:20:02 +0000
  • fe50d09cc8 added new payload for PostgreSQL (parameter replace) Miroslav Stampar 2011-05-18 23:01:41 +0000
  • 9832fc42d4 minor improvement for --tamper (now standard tamper scripts can be used like --tamper=randomcase) Miroslav Stampar 2011-05-18 21:47:40 +0000
  • 3048e9f710 minor refactoring Miroslav Stampar 2011-05-17 23:03:31 +0000
  • cc07e5dc97 added --charset option to force charset encoding of the retrieved data (e.g. when the backend collation is different than the current web page charset) as requested by devon.mitchell1988@y​ahoo.com Miroslav Stampar 2011-05-17 22:55:22 +0000
  • dfe81cc66f minor yielding Miroslav Stampar 2011-05-16 20:14:10 +0000
  • a5ad4621c9 minor refactoring Miroslav Stampar 2011-05-16 20:09:12 +0000
  • ba1df457ab fix for a charset euc_tw reported by devon.mitchell1988@y​ahoo.com Miroslav Stampar 2011-05-16 19:26:58 +0000