Commit Graph

  • 940c225d7c few fixes Miroslav Stampar 2011-04-10 20:53:27 +0000
  • d324704844 Removed unused code Bernardo Damele 2011-04-10 20:39:15 +0000
  • 9840a0491d more doc updates Bernardo Damele 2011-04-10 20:31:29 +0000
  • fbf8e7f32d Minor bug fix to --file-read Bernardo Damele 2011-04-10 19:53:42 +0000
  • decab6642d fix for that @chunk bug Miroslav Stampar 2011-04-10 16:46:33 +0000
  • 7dd5bd9d59 Minor fix for --cleanup on MSSQL Bernardo Damele 2011-04-10 13:48:29 +0000
  • 6d165861c8 Minor version increase Bernardo Damele 2011-04-10 13:30:27 +0000
  • fe16360acb more doc updates Bernardo Damele 2011-04-10 13:28:14 +0000
  • 723a7447b2 minor refactoring Miroslav Stampar 2011-04-10 07:16:19 +0000
  • c714ac6421 added support for handling binary data values (no more garbish chars) Miroslav Stampar 2011-04-09 23:13:16 +0000
  • 4ad73f9263 added two new valuable functions for dealing with binary data (e.g. binary representations of password hashes) and some cosmetics Miroslav Stampar 2011-04-09 22:39:03 +0000
  • 277f16d6b3 removing commented out debug print Miroslav Stampar 2011-04-08 22:44:05 +0000
  • c4c40308c6 no more annoying "no metasploit found" for case when msfpath provided with root directory of Metasploit (not the bin one) Miroslav Stampar 2011-04-08 22:42:07 +0000
  • 83feb097ef greater flexibility for --batch when default is None Miroslav Stampar 2011-04-08 22:29:50 +0000
  • 6fa2fd139c implemented support for __pivotDumpTable on MSSQL as normal tables tend to not play well with normal TOP 1 ..NOT IN..ORDER BY mechanism if the argument for ORDER BY is not the unique one (returns only number of rows equal to the number of distinct values for that field) Miroslav Stampar 2011-04-08 15:17:57 +0000
  • beb98140b3 Minor improvement to --check-payload Bernardo Damele 2011-04-08 14:34:00 +0000
  • d5fb1378cc Gone unnoticed for way too long Bernardo Damele 2011-04-08 11:15:19 +0000
  • 228cc68747 fix for those ugly DEBUG messages in brute mode Miroslav Stampar 2011-04-08 11:02:21 +0000
  • 5b21352656 cosmeticados ;) Bernardo Damele 2011-04-08 10:39:07 +0000
  • 64fcc88be5 typo Bernardo Damele 2011-04-08 10:26:03 +0000
  • 1be7f859c6 Minor updates Bernardo Damele 2011-04-08 10:25:37 +0000
  • bcc4c52cf7 minor update Miroslav Stampar 2011-04-08 10:21:45 +0000
  • 159789ba81 More user's manual updates Bernardo Damele 2011-04-08 10:20:42 +0000
  • d305183447 More updates to user's manual Bernardo Damele 2011-04-08 09:50:34 +0000
  • be11e2535e one more minor update Miroslav Stampar 2011-04-08 00:05:44 +0000
  • 3435d549a9 minor update regarding the last commit Miroslav Stampar 2011-04-07 23:35:51 +0000
  • 726155383d higher compatibility with MSSQL 2000 ("ORDER BY items must appear in the select list if the statement contains a UNION operator.") as we always take the first field from the list as the one for referencing (field = expressionFieldsList[0]) Miroslav Stampar 2011-04-07 23:32:07 +0000
  • e8259a7665 minor update (now --dump also supports only -D parameter) Miroslav Stampar 2011-04-07 22:38:13 +0000
  • bac53eeef1 Allow --dump-all to accept -D switch in order to dump all tables' entries for only one (or more, comma-separated) specified database(s) Bernardo Damele 2011-04-07 22:08:10 +0000
  • b288e5ef57 implemented DNS caching mechanism Miroslav Stampar 2011-04-07 21:39:18 +0000
  • ae4ea0af45 fix for a bug reported by m4l1c3 (AttributeError: 'NoneType' object has no attribute 'replace') Miroslav Stampar 2011-04-07 13:57:07 +0000
  • 02eeeccd33 Added UNION query SQL injection tests also with a random number for columns (not only NULL) Bernardo Damele 2011-04-07 13:39:36 +0000
  • 6a8a5db9aa minor code restyling Miroslav Stampar 2011-04-07 13:27:29 +0000
  • e33a48d40f minor refactoring Miroslav Stampar 2011-04-07 12:54:30 +0000
  • c6b9d89d31 Accept [RANDNUM] as <char> in payloads.xml and handle it accordingly Bernardo Damele 2011-04-07 11:10:35 +0000
  • ca009e9fe2 minor update Miroslav Stampar 2011-04-07 10:43:19 +0000
  • 672abc27fd minor adjustment of livetests for new flavor of --technique Miroslav Stampar 2011-04-07 10:41:12 +0000
  • 9e8c933333 cosmetics Bernardo Damele 2011-04-07 10:40:58 +0000
  • 68828d68a5 removed integers from --technique Miroslav Stampar 2011-04-07 10:37:48 +0000
  • fced81b6be minor update Miroslav Stampar 2011-04-07 10:32:39 +0000
  • 845533e92f minor refactoring Miroslav Stampar 2011-04-07 10:27:22 +0000
  • 1880f18367 Minor layout adjustments Bernardo Damele 2011-04-07 10:07:52 +0000
  • 17844eb87c Refactoring to --technique Bernardo Damele 2011-04-07 10:00:47 +0000
  • 287f74dbd2 update Bernardo Damele 2011-04-06 14:59:51 +0000
  • 05d12790f1 closes #219 - unhidden switch --technique and adapted code accordingly (renamed conf.technique to conf.tech to fit properly in the -h help message) Bernardo Damele 2011-04-06 14:41:44 +0000
  • 8b14a9eaa7 Minor code adjustments Bernardo Damele 2011-04-06 14:40:45 +0000
  • a379463213 cosmeticado Miroslav Stampar 2011-04-06 08:40:06 +0000
  • b327bbcd9b minor fix (it was quite ... to have this check at the later stage) Miroslav Stampar 2011-04-06 08:39:24 +0000
  • fdef6726cf minor update Miroslav Stampar 2011-04-06 08:30:50 +0000
  • 72555f3b28 user's manual updated.. we are getting close to 0.9 stable, stay tuned! Bernardo Damele 2011-04-06 08:21:13 +0000
  • d436ba2da5 Minor "fix" when reading hashes from a local sqlite3 (result of --replicate) and there is an int as value Bernardo Damele 2011-04-06 08:19:56 +0000
  • 81034140c0 Reduced number of threads to 3 when -o is provided Bernardo Damele 2011-04-06 08:15:20 +0000
  • 265fa52600 minor code cosmetics Miroslav Stampar 2011-04-04 18:24:16 +0000
  • 018b6b9430 fix for a charset encoding reported by Kirill Miroslav Stampar 2011-04-04 18:20:09 +0000
  • a1bde071d8 Minor adjustments Bernardo Damele 2011-04-04 09:26:20 +0000
  • 2c01fc56e6 minor update regarding misusage of --proxy and --ignore-proxy switches Miroslav Stampar 2011-04-04 09:19:43 +0000
  • 3253882071 minor cosmetics on tamper scripts Miroslav Stampar 2011-04-04 08:18:26 +0000
  • 33d987805d minor revisit of encoding tampering scripts Miroslav Stampar 2011-04-04 08:11:11 +0000
  • e957c4400c minor revisit of tampering script(s) functionality (urlencode one is removed as it's currently obsolete regarding the whole process of automatic urlencoding) Miroslav Stampar 2011-04-04 08:04:47 +0000
  • 305115a68b important improvement of data handling (POST data and header values) Miroslav Stampar 2011-04-03 15:02:52 +0000
  • bbd4c128b0 minor update related to the last commit Miroslav Stampar 2011-04-01 22:19:42 +0000
  • cd7e4f5afc improvement for lots of multiple-selection forms (now by default the first one is selected - till now it was left unchecked which lead to blank get/post data for the whole form) Miroslav Stampar 2011-04-01 22:12:24 +0000
  • c3b54cc222 Cosmetics Bernardo Damele 2011-04-01 16:40:28 +0000
  • e27afef6be minor update regarding --current-db on Oracle Miroslav Stampar 2011-04-01 15:56:11 +0000
  • eb99f68a7a Minor improvement to --wizard. This does not mean I like the kiddie feature though ;) Bernardo Damele 2011-04-01 14:55:39 +0000
  • de4e0c7346 minor update related to the problem with request files reported by jorge_a_santos@hotmail.com Miroslav Stampar 2011-04-01 12:09:11 +0000
  • 60102209f6 quick fix for a bug reported by Kirill (AttributeError: 'NoneType' object has no attribute 'split') Miroslav Stampar 2011-04-01 11:14:24 +0000
  • ee15988878 another minor update related to previous commit Miroslav Stampar 2011-03-31 17:34:07 +0000
  • 156d24203f speed optimization Miroslav Stampar 2011-03-31 17:16:26 +0000
  • 220366b6e8 minor update (ip addresses will not be confused any more for crypt_generic hashes) Miroslav Stampar 2011-03-31 16:56:26 +0000
  • 557ed7d665 minor fix for a invalid charset reported by Kirill Miroslav Stampar 2011-03-31 14:39:01 +0000
  • fed57282fc Added one more warning message to show what's going on with ctrl+c Bernardo Damele 2011-03-31 14:26:14 +0000
  • 3948cd9e77 Minor layout adjustments Bernardo Damele 2011-03-31 14:13:53 +0000
  • 60afd80460 Change of release date to unknown Bernardo Damele 2011-03-31 13:06:30 +0000
  • c5de903eab minor improvement ("quick defense against substr fields") Miroslav Stampar 2011-03-31 09:35:09 +0000
  • ce51326bff quick fix Miroslav Stampar 2011-03-31 08:43:17 +0000
  • 0916117447 improvement of error-based testing (no more sqlmap aborting on error-based payloads which happens very often on MySQL servers); also, minor improvement on brute forcing of column names Miroslav Stampar 2011-03-30 18:32:10 +0000
  • dd01d66f13 proper update regarding last commit Miroslav Stampar 2011-03-29 22:10:08 +0000
  • 850328df6c minor cosmetics Miroslav Stampar 2011-03-29 22:03:48 +0000
  • b6af80bab3 refactoring, cleanup and improvement Miroslav Stampar 2011-03-29 21:54:15 +0000
  • adfbfef8c1 minor refactoring Miroslav Stampar 2011-03-29 21:01:47 +0000
  • 12f3024c8a removing that boring message "reflective value found and filtered out" for headers case (we always include Uri header) Miroslav Stampar 2011-03-29 20:45:21 +0000
  • 9f707febf5 minor update Miroslav Stampar 2011-03-29 15:43:17 +0000
  • d0861a00e2 minor improvement Miroslav Stampar 2011-03-29 15:37:57 +0000
  • d28ca5809b adding support for meta HTML header 'refresh' - popular one amongst login pages (stumbled when tested blind injections on Mutillidae login page) Miroslav Stampar 2011-03-29 14:16:28 +0000
  • 7cf4ba83dc minor refactoring and comment update Miroslav Stampar 2011-03-29 12:08:07 +0000
  • 1821a008af Ctrl+C in dictionary attack phase will now not abort the whole enumeration; also, question for common suffixes will now be asked only once Miroslav Stampar 2011-03-29 12:00:29 +0000
  • 5560196648 minor fix Miroslav Stampar 2011-03-29 11:50:12 +0000
  • e20d460809 Bernardo will kill me (added --wizard for total beginners) Miroslav Stampar 2011-03-29 11:42:55 +0000
  • 4d78eac938 revert of that thingy as requested by Bernardo Miroslav Stampar 2011-03-29 10:06:35 +0000
  • a9f5d828c6 minor fix avoiding problems with hashing strange characters in usernames Miroslav Stampar 2011-03-29 07:50:07 +0000
  • b7813f9e68 incrementing level for MySQL stacked payloads Miroslav Stampar 2011-03-29 07:31:56 +0000
  • e8debbe724 minor cosmetics and one minor fix (|= is a nono with None) Miroslav Stampar 2011-03-29 06:38:19 +0000
  • 86f93713d3 fix for a bug reported by m4l1c3 (object of type 'NoneType' has no len()) and minor update Miroslav Stampar 2011-03-29 06:25:17 +0000
  • a2d5358b08 minor fix Miroslav Stampar 2011-03-28 23:40:46 +0000
  • 9e900ccbac minor comment update Miroslav Stampar 2011-03-28 23:12:04 +0000
  • a61e287d23 making updates for dummy Windows users Miroslav Stampar 2011-03-28 23:09:19 +0000
  • bf0e3c4662 improvement for --forms with empty fields Miroslav Stampar 2011-03-28 22:48:00 +0000
  • 1823c116bb minor update for special cases of union testing results Miroslav Stampar 2011-03-28 21:45:38 +0000
  • ae53ad4c30 making an update for special case of timed out response Miroslav Stampar 2011-03-28 21:05:04 +0000