Commit Graph

  • d974a966b8 minor fix for end phase (Ctrl+C) Miroslav Stampar 2010-12-21 23:55:55 +0000
  • fb75d0636b minor update Miroslav Stampar 2010-12-21 23:42:59 +0000
  • 39a13077c4 minor bug fix Miroslav Stampar 2010-12-21 23:09:41 +0000
  • 09479c85dc minor bug fix Miroslav Stampar 2010-12-21 22:35:44 +0000
  • f905adb7c1 way better as there is no official release version for FOUND_ROWS() (it appears somewhere in alphas/betas of 4.0.x - i've stumbled upon one site with 4.0.22 and it didn't recognized FOUND_ROWS). Miroslav Stampar 2010-12-21 22:18:27 +0000
  • 7a525f28d4 cosmetics Miroslav Stampar 2010-12-21 15:26:23 +0000
  • b2e7f9484d minor tuning (2 techniques MAX per value used) Miroslav Stampar 2010-12-21 15:24:14 +0000
  • 6c1133c4d4 some code refactoring Miroslav Stampar 2010-12-21 15:13:13 +0000
  • 466d61ee85 minor fix Miroslav Stampar 2010-12-21 14:29:47 +0000
  • 385e208f38 code refactoring regarding standard output suppression and some threading issues Miroslav Stampar 2010-12-21 14:21:24 +0000
  • 0e68248f60 minor update of heuristic check Miroslav Stampar 2010-12-21 12:56:18 +0000
  • 16f1f4e13e when doing dynamic checks there are cases when 404 can be raised (perfectly normal) Miroslav Stampar 2010-12-21 11:04:49 +0000
  • aca074b769 Removed unused outdated code Bernardo Damele 2010-12-21 10:49:52 +0000
  • ad6b528b33 Bit more verbose comment Bernardo Damele 2010-12-21 10:47:39 +0000
  • 6b37ddada4 removed some blank trailing spaces (with extra/shutils/blanks.sh) Miroslav Stampar 2010-12-21 10:31:56 +0000
  • 1a3f57e5fe Cosmetics Bernardo Damele 2010-12-21 09:23:00 +0000
  • d554460aec minor fix Miroslav Stampar 2010-12-21 01:09:39 +0000
  • 116c141dfa another fix Miroslav Stampar 2010-12-21 00:47:07 +0000
  • 416755c0b7 minor adjustments Miroslav Stampar 2010-12-21 00:25:03 +0000
  • a876fcedfb minor update Miroslav Stampar 2010-12-21 00:13:50 +0000
  • 8067365b93 fix for a bug reported by m4l1c3 (AttributeError: '_MainThread' object has no attribute 'ident') Miroslav Stampar 2010-12-20 23:47:53 +0000
  • e10670d9ac added end detection phase choice into Ctrl+C list Miroslav Stampar 2010-12-20 23:34:00 +0000
  • 03b275ce33 update Miroslav Stampar 2010-12-20 23:27:04 +0000
  • 29001a4fce minor update Miroslav Stampar 2010-12-20 23:21:01 +0000
  • 518b3e094c bug fix (http://dev.mysql.com/doc/refman/5.0/en/information-functions.html#function_found-rows) Miroslav Stampar 2010-12-20 23:00:03 +0000
  • b34fe5c334 no more need for such a huge timeout because any timeout exceptions will now be considered as a successful time-based attack (previously we wanted to get back to the program, hence there was such a huge timeout) Miroslav Stampar 2010-12-20 22:49:48 +0000
  • 8fd3e7ba1f thread based data added Miroslav Stampar 2010-12-20 22:45:01 +0000
  • c9e8aae8a2 we'll need to do some cleanup around threading data model we use (some of the data we currently use we'll need to spread via copies around used threads) Miroslav Stampar 2010-12-20 19:34:41 +0000
  • e09bc2406c minor refactoring Miroslav Stampar 2010-12-20 19:24:20 +0000
  • 5852bad963 some refactoring Miroslav Stampar 2010-12-20 18:56:06 +0000
  • 36999a07c4 some filtering Miroslav Stampar 2010-12-20 17:41:41 +0000
  • 19d8733e9a this is strictly for educational purposes Miroslav Stampar 2010-12-20 17:30:47 +0000
  • c948bced61 should solve the problem with timeout problems in time-based payloads Miroslav Stampar 2010-12-20 16:45:41 +0000
  • 364bc8e7d4 minor update Miroslav Stampar 2010-12-20 11:25:18 +0000
  • 28da1141cf some fixes (for MySQL < 4.0) Miroslav Stampar 2010-12-20 11:23:57 +0000
  • 76024c455f minor fix (using older commands for basic MySQL check) Miroslav Stampar 2010-12-20 11:15:43 +0000
  • eaf8929085 more minor updates Miroslav Stampar 2010-12-20 10:48:53 +0000
  • fd00ff7a82 minor bug fix Miroslav Stampar 2010-12-20 10:37:03 +0000
  • e791f8f2b7 Minor fix Bernardo Damele 2010-12-20 10:33:24 +0000
  • e9f1ecb9e7 minor update Miroslav Stampar 2010-12-20 10:32:58 +0000
  • 10a7a2dfb2 kids, don't use this at home Miroslav Stampar 2010-12-20 10:13:14 +0000
  • 13d5b2c0ff code refactoring Miroslav Stampar 2010-12-20 09:44:21 +0000
  • 4cb83654dc minor update Miroslav Stampar 2010-12-18 16:28:21 +0000
  • 36862e2efa update Miroslav Stampar 2010-12-18 15:57:47 +0000
  • 21d083272e minor minor fix Miroslav Stampar 2010-12-18 14:31:41 +0000
  • 4f73feec2f now dictionary attack on multiple hash formats is supported (like mysql_passwd and mysql_old_passwd in one database) Miroslav Stampar 2010-12-18 14:11:49 +0000
  • 71cf0bd2a5 minor update Miroslav Stampar 2010-12-18 13:08:37 +0000
  • 05c6d661e8 cosmetics Miroslav Stampar 2010-12-18 10:49:49 +0000
  • 03220d34ba added Ctrl+C check in detection phase Miroslav Stampar 2010-12-18 10:42:09 +0000
  • e355f92f22 bug fix Miroslav Stampar 2010-12-18 10:02:01 +0000
  • fe67d3827c code refactoring and some fixes Miroslav Stampar 2010-12-18 09:51:34 +0000
  • a067e805fa minor update Miroslav Stampar 2010-12-17 22:23:01 +0000
  • 108a96c6b4 some fixes Miroslav Stampar 2010-12-17 21:45:20 +0000
  • a19cb2c13a code refactoring (added UNKNOWN_DBMS_VERSION instead of "Unknown") Miroslav Stampar 2010-12-17 21:29:09 +0000
  • b4450c6ddd added one more level of MSSQL version check (if first fails for some reason) Miroslav Stampar 2010-12-17 21:01:14 +0000
  • 07609bfb53 minor fix Miroslav Stampar 2010-12-17 19:33:20 +0000
  • bfdc4fa000 new error vector for MS SQL (from David Guimaraes' mail) Miroslav Stampar 2010-12-17 19:00:20 +0000
  • 323af45ce4 added one more time request payload to confirm test results Miroslav Stampar 2010-12-17 07:53:58 +0000
  • e3fa3b0e8e fix for a minor bug reported by nightman (AttributeError: 'NoneType' object has no attribute 'getFingerprint') Miroslav Stampar 2010-12-17 07:48:32 +0000
  • 95b2c0803b minor fix Miroslav Stampar 2010-12-15 20:51:29 +0000
  • de54219571 code refactoring Miroslav Stampar 2010-12-15 12:50:56 +0000
  • cda00c7501 code refactoring Miroslav Stampar 2010-12-15 12:43:56 +0000
  • 3f34b06a24 minor cosmetics Miroslav Stampar 2010-12-15 12:34:14 +0000
  • 445cc3bf3c minor cosmetics Miroslav Stampar 2010-12-15 12:15:43 +0000
  • c1c525aaea quick fix of a fix Miroslav Stampar 2010-12-15 12:10:33 +0000
  • 7cfeb5447b minor update Miroslav Stampar 2010-12-15 11:46:28 +0000
  • 4dec24d056 quick fix for a bug reported by Andreas Constantinides (KeyError: 5) Miroslav Stampar 2010-12-15 11:30:29 +0000
  • f8a01ddaf8 minor update Miroslav Stampar 2010-12-15 11:21:47 +0000
  • 63f5c35c23 bug fix Miroslav Stampar 2010-12-15 10:02:58 +0000
  • 3ee44584d4 i've found a way! thank you hesus! fyea (ASC(MID) was just crashing when MID returned 'empty string') Miroslav Stampar 2010-12-14 12:57:59 +0000
  • c3d0295d21 minor update (checking for --time-sec value) Miroslav Stampar 2010-12-14 12:37:21 +0000
  • b75d7fa348 minor cache based optimization Miroslav Stampar 2010-12-14 12:22:17 +0000
  • 270ae0f080 just in case as maybe there will be some boolean expression to check where we won't expect None, but explicitly True/False Miroslav Stampar 2010-12-14 09:05:00 +0000
  • 4c6e902471 removed obsolete comment Miroslav Stampar 2010-12-14 07:49:30 +0000
  • 04caef6de0 Tuning Bernardo Damele 2010-12-13 23:04:26 +0000
  • cfcee6439e Cosmetics Bernardo Damele 2010-12-13 21:55:30 +0000
  • 86690682c7 Minor bug fix to respect -v value in --common-tables and --common-columns Bernardo Damele 2010-12-13 21:37:12 +0000
  • 4b79227b5a Minor bug fix to properly merge options from .conf file (-c) with command line switches Bernardo Damele 2010-12-13 21:36:23 +0000
  • db844c1785 No point in showing the error-based inject payload, it's same as the one showed in -v3 Bernardo Damele 2010-12-13 21:35:20 +0000
  • 698f30e65e Cosmetics Bernardo Damele 2010-12-13 21:34:35 +0000
  • a02dd6b55b Minor enhancement to speedup active dbms fingerprint (-f). Code cleanup and refactoring. Bernardo Damele 2010-12-13 21:33:42 +0000
  • 207f63cebc Prepare for UNION query tests at detection phase Bernardo Damele 2010-12-13 21:31:34 +0000
  • d56f47d530 fix for a bug reported by black zero (ValueError: invalid literal for int() with base 10: '1-20') Miroslav Stampar 2010-12-12 23:59:55 +0000
  • 33639578ee minor update for MS Access Miroslav Stampar 2010-12-12 15:25:19 +0000
  • 6a3c4485e6 minor update (removing extra ()) Miroslav Stampar 2010-12-12 14:44:39 +0000
  • e98d9c08e1 dumping table is now possible on Firebird too Miroslav Stampar 2010-12-12 14:38:07 +0000
  • f9bc6fc78f minor fix Miroslav Stampar 2010-12-11 22:14:35 +0000
  • c93634b6c7 blind dumping of tables in sqlite implemented Miroslav Stampar 2010-12-11 22:13:19 +0000
  • b1babeefe5 update regarding dumping of tables with blind on Sqlite Miroslav Stampar 2010-12-11 22:00:16 +0000
  • f7344a5fc3 update Miroslav Stampar 2010-12-11 21:28:11 +0000
  • 6a24048aa6 urllib2 doesn't play well with '\n' when non unescaped chars used Miroslav Stampar 2010-12-11 21:17:54 +0000
  • e6c66fa37c update regarding expectingNone in fingerprinting mode to cancel drop down to other techniques available Miroslav Stampar 2010-12-11 17:55:28 +0000
  • e32fa9df43 further update regarding bugtrace's report Miroslav Stampar 2010-12-11 17:32:15 +0000
  • 5d18c98ec2 quick fix for a bug reported by bugtrace (not using __goBooleanProxy because we don't have a proper vector this moment) Miroslav Stampar 2010-12-11 17:20:39 +0000
  • 03447acc1d avoiding some trashy match ratios Miroslav Stampar 2010-12-11 17:12:19 +0000
  • d2a3e8f44f first time firebird error-based query success Miroslav Stampar 2010-12-11 11:17:24 +0000
  • acc7d6d40c fix Miroslav Stampar 2010-12-11 11:03:32 +0000
  • f021548bd0 added inference failsafe (like in for instance Firebirds SUBSTR always returns a string value, no matter which starting index you use) Miroslav Stampar 2010-12-11 10:52:04 +0000
  • c17f444aab minor fix Miroslav Stampar 2010-12-11 10:22:18 +0000
  • 1beb1dd2cc minor update Miroslav Stampar 2010-12-11 09:30:38 +0000