Commit Graph

  • 92e4cdb241 raising critical when google detects strange traffic and also removing obsolete sqlmapSiteTooDynamic Miroslav Stampar 2011-01-03 14:21:41 +0000
  • 07129371bf bug fix for time based injections with keepalive (keepalive module has timeout argument which screwed tbMsg); also, bug fix for cases when remote hosts forcefully disconnects the user on some tests (instead of retrying and critically going out, continue with further tests) Miroslav Stampar 2011-01-03 13:04:20 +0000
  • 3629c2737b automatically turn on --text-only in case of heavily-dynamicity instead of critical exit Miroslav Stampar 2011-01-03 11:06:49 +0000
  • adc41181e6 some DBMSes (MS Access for example) don't play well with a simple query suffix OR 1>2 which should represent NOP one Miroslav Stampar 2011-01-03 10:37:20 +0000
  • 5860b8942f minor update Miroslav Stampar 2011-01-03 09:16:42 +0000
  • d19a8d53e4 minor update Miroslav Stampar 2011-01-03 08:46:20 +0000
  • 8625494ff2 added one new quick check for multiple target(s) mode Miroslav Stampar 2011-01-03 08:32:06 +0000
  • 8e1927fe31 minor fix Miroslav Stampar 2011-01-02 18:12:18 +0000
  • 2efe7928c0 more concise than previously Miroslav Stampar 2011-01-02 17:06:13 +0000
  • 5f9b6b2254 code refactoring Miroslav Stampar 2011-01-02 16:51:21 +0000
  • 252ef7626f removing too old user-agents (some sites just reject those because of possible rendering issues) Miroslav Stampar 2011-01-02 15:57:52 +0000
  • a56934e68b one more MSSQL/ASPX error banner regex Miroslav Stampar 2011-01-02 15:36:57 +0000
  • e6f0c4d857 minor update Miroslav Stampar 2011-01-02 15:32:35 +0000
  • c1d0dde769 added support for .NET banners (http://msdn.microsoft.com/en-us/library/system.data.sqlclient.aspx) Miroslav Stampar 2011-01-02 14:46:31 +0000
  • f762f32de8 bug fix for proper --parse-errors on .aspx pages Miroslav Stampar 2011-01-02 13:00:04 +0000
  • b763feafd9 bug fix (TypeError: object of type 'NoneType' has no len()) Miroslav Stampar 2011-01-02 12:26:31 +0000
  • f0dad2a1e4 minor bug fix (in multiple item search only last item was shown) Miroslav Stampar 2011-01-02 12:23:36 +0000
  • 7b9d978cf9 minor fix (database and/or table names with - sign inside needs to be escaped by ` character or will lead to a "SQL syntax") Miroslav Stampar 2011-01-02 11:01:20 +0000
  • dce9a762f1 important update regarding restoring of potentially changed switch values in multi-target mode and/or missing switch values in resume mode Miroslav Stampar 2011-01-02 10:37:32 +0000
  • 96341f8f78 minor fix Miroslav Stampar 2011-01-02 09:16:17 +0000
  • 73e8a10527 minor fix Miroslav Stampar 2011-01-02 09:12:20 +0000
  • 93cb75ff65 added Nginx Miroslav Stampar 2011-01-02 08:50:27 +0000
  • 5c6c870db4 removed some problematic user agents (google won't work with them) and added page rank next to tested item in multi target mode Miroslav Stampar 2011-01-02 08:43:38 +0000
  • 6651ba05eb another fix (OS was set to None at all previous sessions if there was no explicit OS testing done) Miroslav Stampar 2011-01-02 08:08:38 +0000
  • e28b9f26fc minor fix Miroslav Stampar 2011-01-02 08:01:01 +0000
  • da138c46c1 added support for displaying HTTP error codes (particularly interesting ones are 403 and 406 which screw up data retrieval and DBMS fingerprinting badly) Miroslav Stampar 2011-01-02 07:37:47 +0000
  • ec4440108b minor cosmetics Miroslav Stampar 2011-01-02 07:09:04 +0000
  • 428e817a32 some refactoring Miroslav Stampar 2011-01-01 23:57:27 +0000
  • 212035e64d user can now choose if he wants to skip non-heuristic based DBMS tests Miroslav Stampar 2011-01-01 23:38:11 +0000
  • ded9798e3d minor bug fix Miroslav Stampar 2011-01-01 23:07:50 +0000
  • 8a93cfd975 minor update Miroslav Stampar 2011-01-01 22:43:15 +0000
  • 52e44df86c minor update Miroslav Stampar 2011-01-01 21:11:29 +0000
  • 942cbafba6 minor update Miroslav Stampar 2011-01-01 20:19:55 +0000
  • 26b06bfcfb update (http://dev.mysql.com/doc/refman/5.0/en/server-system-variables.html) Miroslav Stampar 2011-01-01 19:38:51 +0000
  • e4fd8b3f0c (e) finally works as it should Miroslav Stampar 2011-01-01 19:22:44 +0000
  • 0e815177c8 minor update Miroslav Stampar 2011-01-01 19:07:40 +0000
  • ef27fd5ea1 there is a huge problem with urllib2 connections that sockets are left opened causing problems with lots of disposable connections used (like in --threads) (http://mail.python.org/pipermail/python-bugs-list/2007-January/036873.html, http://mail.python.org/pipermail/python-bugs-list/2007-January/036873.html) Miroslav Stampar 2011-01-01 15:20:29 +0000
  • 7ea3d060f6 some fixes/updates here and there Miroslav Stampar 2011-01-01 12:41:51 +0000
  • 15e6911fd8 fix for a bug reported by ragos@joker.ms (AttributeError: 'NoneType' object has no attribute 'write') Miroslav Stampar 2011-01-01 12:23:02 +0000
  • 91f665aaaa bug fix for Ctrl+C Miroslav Stampar 2010-12-31 15:00:19 +0000
  • 076560f59f bug fix Miroslav Stampar 2010-12-31 12:58:27 +0000
  • 5db8ebbfa9 update of mysql comment versions Miroslav Stampar 2010-12-31 12:42:12 +0000
  • 40e3489099 minor update Miroslav Stampar 2010-12-31 12:27:57 +0000
  • ce19b0c431 optimization of comment checking in MySQL Miroslav Stampar 2010-12-31 12:21:02 +0000
  • 281d124fa6 minor bug fix Miroslav Stampar 2010-12-31 12:04:39 +0000
  • 42e7b1b3a7 bug fix Miroslav Stampar 2010-12-30 22:40:37 +0000
  • 20e3a6d72f fix/refactor/cosmetics (references: http://www.postgresql.org/docs/6.4/static/release.htm,http://www.postgresql.org/docs/8.2/static/functions-datetime.html#FUNCTIONS-DATETIME-TABLE,http://www.postgresql.org/docs/8.3/static/release-8-3.html) Miroslav Stampar 2010-12-30 21:53:34 +0000
  • 7f4acaf6f9 now comment injection fingerprint works with all techniques Miroslav Stampar 2010-12-30 21:24:26 +0000
  • 6f17e84e19 minor fix Miroslav Stampar 2010-12-30 08:29:20 +0000
  • c3065f6ecc minor fix Miroslav Stampar 2010-12-29 20:38:56 +0000
  • 2476c1516d minor fix Miroslav Stampar 2010-12-29 20:26:36 +0000
  • 613242e298 bug fix (dynamic markings were not restored in program rerun which potentially led to no data retrieved) Miroslav Stampar 2010-12-29 19:48:19 +0000
  • 8f32c740ff code refactoring Miroslav Stampar 2010-12-29 19:39:32 +0000
  • 6700cabc36 minor optimization Miroslav Stampar 2010-12-29 19:01:29 +0000
  • d1f5c1d7b7 now when we "decode page" based on a charset, sanitizeAsciiString only brings unneeded filtering Miroslav Stampar 2010-12-29 15:10:42 +0000
  • 79e97824ef adding user names to the attack dictionary Miroslav Stampar 2010-12-29 00:37:53 +0000
  • 93838fb155 "patch" for a problem reported by black zero (v = self._sslobj.write(data)...UnicodeError) Miroslav Stampar 2010-12-28 14:40:34 +0000
  • 96c3ffd3d7 changing risk level to 0 - lots of MySQL databases around have information_schema unreadable, thus disabling first AND based error payload Miroslav Stampar 2010-12-27 19:02:13 +0000
  • c0423761e8 minor update Miroslav Stampar 2010-12-27 18:27:42 +0000
  • a77b186aca minor fix Miroslav Stampar 2010-12-27 16:55:27 +0000
  • 5015f04826 minor update Miroslav Stampar 2010-12-27 16:36:05 +0000
  • c8f8dbf0a7 minor update Miroslav Stampar 2010-12-27 15:39:27 +0000
  • 9c1676bdfa minor cosmetics Miroslav Stampar 2010-12-27 14:44:00 +0000
  • 9fb0e0fc85 resume of brute forced data is now available Miroslav Stampar 2010-12-27 14:17:20 +0000
  • c7a160bf72 minor update (users want this to see) Miroslav Stampar 2010-12-27 12:00:54 +0000
  • 3d23f226ae minor update Miroslav Stampar 2010-12-27 11:47:50 +0000
  • 68462466f2 minor fix for a bug reported by shaohua pan (argument of type 'NoneType' is not iterable) Miroslav Stampar 2010-12-27 11:36:36 +0000
  • 51a492e17d pretty important commit (now dumped tables are prone to dictionary attack) Miroslav Stampar 2010-12-27 10:56:28 +0000
  • c8d5a6b980 update Miroslav Stampar 2010-12-27 00:41:16 +0000
  • 269d6bde24 this one is pretty complicated (authentication handler tries to call keep alive module, while keep alive module tries to call authentication handler, leading to an infinite recursion) Miroslav Stampar 2010-12-27 00:14:29 +0000
  • 89c2640d23 basic --search now works with MS Access Miroslav Stampar 2010-12-26 23:50:16 +0000
  • f2373121d0 noticed little DoS behavior and lots of connections in netstat (best way to deal with zombie connections is to explicitly close them if not needed any more) Miroslav Stampar 2010-12-26 14:36:51 +0000
  • c4d6a367e9 this way order given in -C is preserved Miroslav Stampar 2010-12-26 14:11:42 +0000
  • c93f2a703d minor update Miroslav Stampar 2010-12-26 14:02:16 +0000
  • ceeb6374e8 bug fix (TypeError: object of type 'NoneType' has no len()) Miroslav Stampar 2010-12-26 13:27:24 +0000
  • 569e060aab important improvement Miroslav Stampar 2010-12-26 13:20:52 +0000
  • fcd01b3018 minor update Miroslav Stampar 2010-12-26 11:24:41 +0000
  • a555d1ad68 minor improvement Miroslav Stampar 2010-12-26 11:15:02 +0000
  • 22ce464efc minor update with local names Miroslav Stampar 2010-12-26 10:16:00 +0000
  • 320a6f9efb minor minor update Miroslav Stampar 2010-12-26 09:55:33 +0000
  • 17d74fc83c cosmeticado Miroslav Stampar 2010-12-26 09:53:40 +0000
  • cd337d9f39 minor fix Miroslav Stampar 2010-12-26 09:46:09 +0000
  • eaf4b93856 minor update Miroslav Stampar 2010-12-26 09:40:40 +0000
  • 562a6440d1 fix for a bug reported by nightman (same as http://bugs.python.org/issue8797) Miroslav Stampar 2010-12-26 09:33:04 +0000
  • 6c72e41972 minor fix/update Miroslav Stampar 2010-12-26 02:19:10 +0000
  • e41acb6fc2 further ms access improvements Miroslav Stampar 2010-12-26 02:13:56 +0000
  • 2c8115eed9 further improvement for ms access table dumping Miroslav Stampar 2010-12-26 01:04:30 +0000
  • 64523212a4 added site:cn Miroslav Stampar 2010-12-26 00:06:47 +0000
  • 5249762794 update Miroslav Stampar 2010-12-25 16:46:33 +0000
  • f85bb96221 columns updated with localized items Miroslav Stampar 2010-12-25 16:26:05 +0000
  • 561121b536 major update adding new table names (based on site:? localization) Miroslav Stampar 2010-12-25 15:15:03 +0000
  • fb099615e2 minor update Miroslav Stampar 2010-12-25 11:16:35 +0000
  • c5c4aae3d5 minor update (to prevent adding too much items) Miroslav Stampar 2010-12-25 10:42:36 +0000
  • b472b96f92 bug fix, refactoring and improved extractErrorMessage capabilities Miroslav Stampar 2010-12-25 10:16:20 +0000
  • ea7ba19f6b minor update Miroslav Stampar 2010-12-25 09:43:14 +0000
  • 272476773f getPageTextWordsSet on tableExists is pretty powerful stuff Miroslav Stampar 2010-12-25 09:37:33 +0000
  • 9853c1ec7f fix for a bug reported by alessio.dallapiazza@gmail.com (AttributeError: users) Miroslav Stampar 2010-12-25 09:13:57 +0000
  • 6845d402fa well, here and there, merry Christmas to all :) Miroslav Stampar 2010-12-24 20:17:53 +0000
  • 706d8e0b88 development update (basic ms access dumping implemented) Miroslav Stampar 2010-12-24 19:53:11 +0000
  • 2d115e0350 one more fix Miroslav Stampar 2010-12-24 18:44:13 +0000