Miroslav Stampar
f1c102a020
Minor touch for internal re-hashing purposes
2017-10-02 16:32:37 +02:00
Miroslav Stampar
834ea2d0d8
Merge pull request #2728 from syedafzal/add_new_waf
...
Added identification for waf NAXSI
2017-10-02 16:29:47 +02:00
Syed Afzal
ae972de8fc
Added identification for waf NAXSI
2017-10-01 22:15:02 +05:30
Miroslav Stampar
62519eed04
Minor patch (breaking lines on longer outputs - 100%)
2017-09-26 13:18:37 +02:00
Miroslav Stampar
222fd856fa
Implementation for #2709
2017-09-25 11:32:40 +02:00
Miroslav Stampar
db94d24db1
Initial support for #2709 (more work to be done)
2017-09-21 14:35:24 +02:00
Miroslav Stampar
116c1c8b5c
Minor refactoring
2017-09-20 15:49:18 +02:00
Miroslav Stampar
afc2a42383
Revisiting regexes for DBMS errors
2017-09-20 15:28:33 +02:00
Miroslav Stampar
44664dd7d6
Minor update (based on user request)
2017-09-19 14:36:34 +02:00
Miroslav Stampar
35ba94b3a9
Fixes #2696
2017-09-17 23:56:48 +02:00
Miroslav Stampar
24c261d630
Minor patch
2017-09-17 23:12:57 +02:00
Miroslav Stampar
6a8ea0557c
Minor update
2017-09-15 14:23:55 +02:00
Miroslav Stampar
721bf4d243
Minor update related to the #2695
2017-09-14 13:28:24 +02:00
Miroslav Stampar
e02ce4eb1f
Merge pull request #2695 from Zwirzu/master
...
Created polish translaton
2017-09-14 13:24:35 +02:00
Zwirzu
2f8e8a5f62
Created polish translaton
...
I just translated Readme.md to polish.
2017-09-14 00:03:24 +02:00
Miroslav Stampar
7de63a7efb
Fixes #2694
2017-09-12 10:32:22 +02:00
Miroslav Stampar
12f802c70f
Minor text update
2017-09-11 10:41:50 +02:00
Miroslav Stampar
96ffb4b911
Fixes #2693
2017-09-11 10:38:19 +02:00
Miroslav Stampar
93cb879e5d
Fixes #2692
2017-09-11 10:17:02 +02:00
Miroslav Stampar
f67f26cebd
Minor update
2017-09-11 10:00:35 +02:00
Miroslav Stampar
942ac7733a
Fixes #2691
2017-09-09 22:27:40 +02:00
Miroslav Stampar
2496db9d96
Update for #2690
2017-09-08 11:59:26 +02:00
Miroslav Stampar
a3249019d9
Patch for an Issue #2690
2017-09-08 11:43:10 +02:00
Miroslav Stampar
96f80879ff
Fixes #2688
2017-09-06 23:41:56 +02:00
Miroslav Stampar
96b9950f96
Fixes #2684
2017-09-05 13:13:08 +02:00
Miroslav Stampar
30ea219228
Fixes #2604
2017-09-05 12:48:51 +02:00
Miroslav Stampar
7c41bc57e7
Fixes #2683
2017-09-05 10:51:58 +02:00
Miroslav Stampar
e609bd04ad
Fixes #2678
2017-09-04 23:00:16 +02:00
Miroslav Stampar
511f2a6d12
Update for #2680
2017-09-04 17:16:00 +02:00
Miroslav Stampar
415ce05a2f
Fixes #2677
2017-09-04 17:05:48 +02:00
Miroslav Stampar
06deda3223
Fixes #2672
2017-09-01 14:29:52 +02:00
Miroslav Stampar
d4170f11f0
Patch for #2654
2017-08-28 17:29:46 +02:00
Miroslav Stampar
cb2258fea4
Fixes #2603
2017-08-28 13:02:08 +02:00
Miroslav Stampar
c871cedae4
Adding hidden option '--force-dbms' to skip fingerprinting
2017-08-28 12:30:42 +02:00
Miroslav Stampar
3e4130c5e6
Update for #2665
2017-08-28 11:08:36 +02:00
Miroslav Stampar
a6c04a59cb
Minor update
2017-08-23 14:10:11 +02:00
Miroslav Stampar
53eb44304f
Proper patch for #2666
2017-08-23 14:08:40 +02:00
Miroslav Stampar
400339a884
Fixes #2665
2017-08-23 13:52:51 +02:00
Miroslav Stampar
8b0c50f25d
Update related to the #2663
2017-08-23 13:17:37 +02:00
Miroslav Stampar
e42b63f51c
Typo fix
2017-08-20 10:02:26 +02:00
Miroslav Stampar
b8f88a079a
Fixes #2659
2017-08-20 10:00:04 +02:00
Miroslav Stampar
a761e1d165
Fixes #2656
2017-08-16 03:08:58 +02:00
Miroslav Stampar
5b6926ae05
Fixes #2654
2017-08-11 11:48:05 +02:00
Miroslav Stampar
e862da6d4e
Update for an Issue #2653
2017-08-11 10:47:32 +02:00
Miroslav Stampar
1ac0704c09
Fixes #2651
2017-08-09 16:52:36 +02:00
Miroslav Stampar
b6b51bea9d
Fixes #2649
2017-08-07 11:27:22 +02:00
Miroslav Stampar
672abe8416
Minor just in case update
2017-08-04 13:59:15 +02:00
Miroslav Stampar
fac6712a35
Implements #2647 (Basic authorization for sqlmapapi)
2017-08-04 13:37:49 +02:00
Miroslav Stampar
68ee1f361b
Fixes #2640
2017-07-31 14:20:59 +02:00
Miroslav Stampar
62ae149464
Minor patch
2017-07-29 03:35:05 +02:00
Miroslav Stampar
f071c8500c
Fixes #2634
2017-07-29 03:18:49 +02:00
Miroslav Stampar
5745d650f8
Fixes #2635
2017-07-29 02:42:20 +02:00
Miroslav Stampar
de8ea53d46
Fixes #2628
2017-07-28 00:37:33 +02:00
Miroslav Stampar
23081f83db
Fixes #2626
2017-07-28 00:16:06 +02:00
Miroslav Stampar
4d56a806e8
Minor patch
2017-07-28 00:00:09 +02:00
Miroslav Stampar
1745bac0ab
Fixes #2625
2017-07-26 00:54:29 +02:00
Miroslav Stampar
0f9c81965b
Implementation on request
2017-07-26 00:24:13 +02:00
Miroslav Stampar
d12b65d38c
Fixes #2624
2017-07-25 23:32:30 +02:00
Miroslav Stampar
38c70d9799
Minor update
2017-07-21 11:09:00 +02:00
Miroslav Stampar
a9a744fec6
Merge pull request #2620 from delvelabs/mark-steps-in-har
...
Fix HAR validation for HAR viewer
2017-07-21 11:07:16 +02:00
Louis-Philippe Huberdeau
3c5ee552f0
Make sure non-optional properties are present
2017-07-20 08:50:03 -04:00
Miroslav Stampar
8ca45695ab
Minor update
2017-07-20 03:09:09 +02:00
Miroslav Stampar
bf40526785
Merge pull request #2618 from delvelabs/mark-steps-in-har
...
Mark steps in HAR file
2017-07-20 02:52:57 +02:00
Miroslav Stampar
9b41efcbe1
Minor patch
2017-07-20 02:50:34 +02:00
Miroslav Stampar
36f3fd72e6
Update for an Issue #2616
2017-07-20 02:41:47 +02:00
Louis-Philippe Huberdeau
facc54f60b
Receiving some messages with a differerent header line
2017-07-19 15:40:07 -04:00
Louis-Philippe Huberdeau
4c7da11331
Make sure the comment is not set to None
2017-07-19 14:46:36 -04:00
Louis-Philippe Huberdeau
e21f67715c
List is not a valid input type for timings, expecting object
2017-07-19 14:12:30 -04:00
Louis-Philippe Huberdeau
e38267a61e
Include tracking properties in the HAR to identify which test the requests were associated to
2017-07-18 15:46:52 -04:00
Miroslav Stampar
7d147f613f
Fixes #2611
2017-07-17 22:24:51 +02:00
Miroslav Stampar
591a60bbde
Fixes #2606
2017-07-11 14:48:22 +02:00
Miroslav Stampar
3f40bf1101
Fixes #2387
2017-07-06 11:44:18 +02:00
Miroslav Stampar
d248317b89
Update for people that just download 'sqlmap.py' <- they exist
2017-07-05 16:42:54 +02:00
Miroslav Stampar
75fd878242
Minor patch
2017-07-05 15:41:53 +02:00
Miroslav Stampar
30378c8ae3
Minor patch
2017-07-05 15:27:29 +02:00
Miroslav Stampar
c9b3b47d6f
Minor update
2017-07-05 14:07:21 +02:00
Miroslav Stampar
d038d027f9
Minor updates
2017-07-05 13:51:48 +02:00
Miroslav Stampar
c6577b80d9
Minor update
2017-07-05 13:35:02 +02:00
Miroslav Stampar
4a4fa07bdd
Minor update
2017-07-05 12:35:48 +02:00
Miroslav Stampar
a4ebd5418f
Patch for an Issue reported privately via email
2017-07-05 12:15:14 +02:00
Miroslav Stampar
ba369b73d3
Fixes #2601
2017-07-05 11:31:42 +02:00
Miroslav Stampar
614f290217
Update for #2597
2017-07-04 12:14:17 +02:00
Miroslav Stampar
1678b606a2
Update for #2597
2017-07-03 16:55:24 +02:00
Miroslav Stampar
aef5d6667f
Merge pull request #2597 from delvelabs/generate-har
...
Generate HAR
2017-07-03 15:27:00 +02:00
Miroslav Stampar
b622c25f9d
Fixes #2598
2017-07-03 14:17:11 +02:00
Miroslav Stampar
e07ff7168b
Fixes #2599
2017-07-02 00:03:34 +02:00
Miroslav Stampar
ce48217ada
Minor update
2017-07-01 23:46:28 +02:00
Louis-Philippe Huberdeau
b6969df52a
Add missing httpVersion in request render, avoid encoding to base64 unless binary data is included
2017-06-29 10:14:20 -04:00
Miroslav Stampar
0e728aa73e
Changing default encoding of sys.argv
2017-06-29 15:33:34 +02:00
Miroslav Stampar
f93c19ba9d
Fixes #2596
2017-06-29 15:29:54 +02:00
Louis-Philippe Huberdeau
dd19527e9c
Remove debug _raw entry from output
2017-06-29 09:00:02 -04:00
Miroslav Stampar
a42ddad9c1
Implements #2583
2017-06-29 14:57:35 +02:00
Miroslav Stampar
a2973296a2
Fixes #2595
2017-06-29 14:26:25 +02:00
Miroslav Stampar
0961f6a5e9
Fixes #2592
2017-06-23 23:46:25 +02:00
Louis-Philippe Huberdeau
fae965f8b6
Parse and build the response block
2017-06-23 13:28:22 -04:00
Louis-Philippe Huberdeau
0d756a8823
Parse request data and convert to HAR, include in injection data
2017-06-23 11:50:21 -04:00
Louis-Philippe Huberdeau
8df4cc3983
Adding initial hook to receive the request/response pairs
2017-06-23 09:44:33 -04:00
Miroslav Stampar
5ec44b8346
Minor refactoring
2017-06-19 23:06:05 +02:00
Miroslav Stampar
d577c57a11
Merge pull request #2590 from neargle/master
...
append %A0 to the blanks set of tamper/space2mysqlblank
2017-06-19 22:51:21 +02:00
neargle
ca24509e19
append %A0 to space2mysqlblank
2017-06-19 22:39:09 +08:00
Miroslav Stampar
e2d3187a78
Fixes #2576
2017-06-18 15:00:12 +02:00
Miroslav Stampar
b4980778dd
Fixes #2577
2017-06-18 14:07:48 +02:00
Miroslav Stampar
71457fea0e
Fixes #2585
2017-06-18 13:19:11 +02:00
Miroslav Stampar
34281af3f6
Minor cleaning
2017-06-14 08:13:41 -04:00
Miroslav Stampar
7dbbf3ecf5
Fixes 'codewatchorg/sqlipy/issues/12'
2017-06-07 23:19:19 +02:00
Miroslav Stampar
c41c93a404
Fixes #2568
2017-06-07 22:43:28 +02:00
Miroslav Stampar
9a7343e9f7
Fixes #2566
2017-06-07 16:07:27 +02:00
Miroslav Stampar
e0401104f2
Minor update
2017-06-07 12:55:14 +02:00
Miroslav Stampar
9da8d55128
Implements #2557
2017-06-07 11:22:06 +02:00
Miroslav Stampar
864711b434
Minor improvement
2017-06-05 16:48:14 +02:00
Miroslav Stampar
996ad59126
Minor patch
2017-06-05 16:28:19 +02:00
Miroslav Stampar
6d48df2454
Fixes #2562
2017-06-05 10:38:05 +02:00
Miroslav Stampar
55a43a837b
Minor update
2017-06-02 00:50:00 +02:00
Miroslav Stampar
455d41c6a0
Merge pull request #2555 from SValkanov/master
...
Bulgarian translation
2017-06-02 00:49:01 +02:00
Miroslav Stampar
eb26dd8984
Fixes #2556
2017-06-02 00:44:01 +02:00
SValkanov
0f34300221
Edit Bulgarian translation
2017-06-01 16:51:00 +03:00
SValkanov
93a875ec71
Edit bulgarian translation
2017-06-01 16:07:47 +03:00
SValkanov
0edb4f6680
Added translation for Bulgarian language
2017-06-01 16:05:06 +03:00
Miroslav Stampar
b9b5d07336
Cleaning leftover
2017-05-30 11:41:42 +02:00
Miroslav Stampar
5f3235ef57
Fixes #2551
2017-05-30 11:40:06 +02:00
Miroslav Stampar
dfe42612be
Fixes #2549
2017-05-29 10:57:27 +02:00
Miroslav Stampar
a0202f7bfd
Fixes #2538
2017-05-26 16:08:30 +02:00
Miroslav Stampar
6dd9d5b2dd
Fixes #2547
2017-05-26 14:34:32 +02:00
Miroslav Stampar
0864387885
Minor update
2017-05-26 14:25:22 +02:00
Miroslav Stampar
359bfb2704
Minor adjustment
2017-05-26 14:14:35 +02:00
Miroslav Stampar
644ea2e3aa
Minor patch
2017-05-26 14:08:08 +02:00
Miroslav Stampar
071132cd56
Fixes #2543
2017-05-21 22:52:44 +02:00
Miroslav Stampar
7a18dde2e0
Merge pull request #2537 from HerendraTJ/patch-1
...
Manual Pengguna -> Panduan Pengguna
2017-05-18 12:13:13 +02:00
HerendraTJ
e146763399
Manual Pengguna -> Panduan Pengguna
...
User Manual -> Panduan Pengguna
2017-05-18 12:59:57 +07:00
Miroslav Stampar
4ce08dcfa3
Patch for an Issue #2536
2017-05-17 00:22:18 +02:00
Miroslav Stampar
2ca5ddce5f
Fixes #2534
2017-05-15 17:03:05 +02:00
Miroslav Stampar
addb2445b7
Minor patch
2017-05-15 00:34:13 +02:00
Miroslav Stampar
4736a525b8
Fixes #2532
2017-05-13 17:28:28 +02:00
Miroslav Stampar
d3a08a2d22
Implementation for an Issue #2505
2017-05-07 23:12:42 +02:00
Miroslav Stampar
ee5b5cdcbc
Fixes #2514
2017-05-04 15:50:34 +02:00
Miroslav Stampar
f3f2c81cec
Minor patch (UTF8 used for HTTP params)
2017-05-04 15:45:15 +02:00
Miroslav Stampar
1e8df40981
Fixes #2499
2017-05-01 23:21:12 +02:00
Miroslav Stampar
389133654e
Fixes #2508
2017-05-01 23:06:37 +02:00
Miroslav Stampar
347ce87e27
Fixes #2511
2017-05-01 22:53:12 +02:00
Miroslav Stampar
ff5a954980
Fixes #2508
2017-04-30 08:32:26 +02:00
Miroslav Stampar
1a8de2aee1
Fixes #2504
2017-04-27 13:18:29 +02:00
Miroslav Stampar
ab08273d82
Fixes #2501
2017-04-23 23:50:30 +02:00
Miroslav Stampar
fbb845ad7c
Fixes #2500
2017-04-23 23:30:51 +02:00
Miroslav Stampar
15a1d55812
Fixes #2500
2017-04-23 23:14:05 +02:00
Miroslav Stampar
4643bd6517
Quick patch for #2498
2017-04-21 17:44:51 +02:00
Miroslav Stampar
1c5f01e2a2
Fixes #2487
2017-04-20 11:54:27 +02:00
Miroslav Stampar
ebbc68853d
Fixes #2496
2017-04-20 10:48:04 +02:00
Miroslav Stampar
3140fd0ca6
Fixes #2495
2017-04-20 10:29:05 +02:00
Miroslav Stampar
5bcbf63ddb
Fixes #2491
2017-04-19 16:13:31 +02:00
Miroslav Stampar
01fbda4bc9
Fixes #2490
2017-04-19 16:13:05 +02:00
Miroslav Stampar
ba22171a51
PEP 3113 cleanup
2017-04-19 14:56:32 +02:00
Miroslav Stampar
fc8eede952
Minor cleanup and one bug fix
2017-04-19 14:46:27 +02:00
Miroslav Stampar
c8a0c525fc
Fixes #2489
2017-04-19 14:19:39 +02:00
Miroslav Stampar
46c7c28919
Implementation for an Issue #2485
2017-04-19 13:56:29 +02:00
Miroslav Stampar
81e3395975
Minor update
2017-04-19 13:35:36 +02:00
Miroslav Stampar
0340ecd38a
Minor patch related to the #2487
2017-04-18 16:49:58 +02:00
Miroslav Stampar
2d05174545
Trivial update
2017-04-18 15:56:24 +02:00
Miroslav Stampar
5f2bb88037
Some code refactoring
2017-04-18 15:48:05 +02:00
Miroslav Stampar
65b02d4ab0
Minor update
2017-04-18 14:22:37 +02:00
Miroslav Stampar
ea58d29e2c
Minor update
2017-04-18 14:11:23 +02:00
Miroslav Stampar
47e0fc36c7
Minor consistency update
2017-04-18 14:02:25 +02:00
Miroslav Stampar
7ebba5614a
Moving brute from techniques to utils
2017-04-18 13:53:41 +02:00
Miroslav Stampar
686f53a7c6
Minor patch
2017-04-16 23:32:58 +02:00
Miroslav Stampar
67a3e8cd75
Minor patch
2017-04-14 13:19:00 +02:00
Miroslav Stampar
d9a931f77a
Minor cleanup
2017-04-14 13:14:53 +02:00
Miroslav Stampar
0e206da7c0
Minor patches (pydiatra)
2017-04-14 13:08:51 +02:00
Miroslav Stampar
81e6dab965
New extra script
2017-04-14 12:54:33 +02:00
Miroslav Stampar
a702dafd03
Fixes #2481
2017-04-14 12:47:24 +02:00
Miroslav Stampar
6b48f6ec26
Merge pull request #2480 from jwilk/spelling
...
Fix typos
2017-04-14 12:22:15 +02:00
Jakub Wilk
06148cd610
Fix typos
2017-04-14 11:37:54 +02:00
Miroslav Stampar
36dfad192f
Better link to user's manual
2017-04-13 12:47:14 +02:00
Miroslav Stampar
9436c43306
Mailing list is dead. Long live the mailing list
2017-04-13 12:40:37 +02:00
Miroslav Stampar
c198fd7939
Update for an Issue #13
2017-04-12 10:54:29 +02:00
Miroslav Stampar
1e092c4e8d
Just in case update for an Issue #2474
2017-04-11 13:34:40 +02:00
Miroslav Stampar
1e310631ab
Minor stability patch
2017-04-11 10:01:37 +02:00
Miroslav Stampar
47ee1a991f
Update for an Issue #2472
2017-04-11 09:47:27 +02:00
Miroslav Stampar
9b3d229294
Fixes #2471
2017-04-10 19:21:22 +02:00
Miroslav Stampar
c74756c3bc
Update regarding the #2467
2017-04-10 16:44:12 +02:00
Miroslav Stampar
1196a1b7f8
Fixes #405
2017-04-10 14:50:17 +02:00
Miroslav Stampar
c2262eda1a
Update of smalldict.txt with 7 (small) more from SecLists
2017-04-07 16:30:36 +02:00
Miroslav Stampar
02eacc32c1
Minor cleanup
2017-04-07 16:30:02 +02:00
Miroslav Stampar
b1a112f72c
Updating wordlist.zip file with 15 dicts from SecLists
2017-04-07 16:18:21 +02:00
Miroslav Stampar
464caf056b
Minor update
2017-04-07 15:55:18 +02:00
Miroslav Stampar
44c85f8351
Reverting back the bottle.py revision because of numerous Python 2.6 incompatibilities
2017-04-07 15:10:28 +02:00
Miroslav Stampar
ad3283fd24
Another Python 2.6 patch
2017-04-07 15:05:54 +02:00
Miroslav Stampar
07208c45ef
Patch of bottle.py for Python 2.6
2017-04-07 14:59:24 +02:00
Miroslav Stampar
751f423ae0
Adding latest revision of bottle.py
2017-04-07 14:55:25 +02:00
Miroslav Stampar
c124086021
Minor update for #1282
2017-04-07 14:46:41 +02:00
Miroslav Stampar
f285bc7459
Minor update
2017-04-07 14:30:52 +02:00
Miroslav Stampar
b4c4d3f72a
Fixes latest Python 2.6 compatibility issues
2017-04-06 11:37:42 +02:00
Miroslav Stampar
cfe34f61b8
Implementation for an Issue #1895
2017-04-06 11:33:59 +02:00
Miroslav Stampar
c1c7ea33fe
Minor update
2017-03-30 12:05:05 +02:00
Miroslav Stampar
4458a443ef
Fixes #1664
2017-03-30 11:58:03 +02:00
Miroslav Stampar
16bd3a1f02
Fixes #2453
2017-03-30 11:42:34 +02:00
Miroslav Stampar
a358bc0a38
Minor update
2017-03-30 10:24:57 +02:00
Miroslav Stampar
aebae6e27b
Added (heuristic) support for #1679
2017-03-30 10:16:35 +02:00
Miroslav Stampar
0a3e771b1b
Fixes #2449
2017-03-28 15:22:53 +02:00
Miroslav Stampar
f82c0497fa
Fixes #2447
2017-03-27 22:36:04 +02:00
Miroslav Stampar
715763885d
Fixes #2306
2017-03-24 14:20:18 +01:00
Miroslav Stampar
4aae5d9a9d
Fixes #2444
2017-03-19 21:34:47 +01:00
Miroslav Stampar
1bc583d358
Another patch related to the #2440
2017-03-17 09:43:45 +01:00
Miroslav Stampar
e506a390db
Minor patch (prevent message spamming of multiple union column possibilities)
2017-03-15 16:18:20 +01:00
Miroslav Stampar
c5b4af8636
Dummy commit (to provoke rehash)
2017-03-15 16:07:52 +01:00
Miroslav Stampar
c29e47f72f
Fixes #2440
2017-03-15 16:04:56 +01:00
Miroslav Stampar
4087213501
Merge pull request #2439 from klensy/mysql-fingerprint-update
...
updated mysql version numbers
2017-03-14 21:15:44 +01:00
klensy
e4725366d3
updated mysql version numbers
2017-03-14 15:11:03 +03:00
Miroslav Stampar
60e8c725f9
Fixes #2437
2017-03-12 23:24:13 +01:00
Miroslav Stampar
5dba32b2e1
Fixes #2431
2017-03-12 09:52:37 +01:00
Miroslav Stampar
ef04c99069
No more dumb usage of '--dbms'
2017-03-06 12:53:04 +01:00
Miroslav Stampar
e2fb16c98c
Fixes #2425
2017-03-06 12:05:58 +01:00
Miroslav Stampar
d2b16c5c91
Fixes #2422
2017-03-01 11:09:55 +01:00
Miroslav Stampar
9f0c42dde0
Minor leftover
2017-03-01 10:09:13 +01:00
Miroslav Stampar
78ca371162
Adding option --web-root (Issue #2419 )
2017-03-01 10:07:26 +01:00
Miroslav Stampar
a35c976759
Proper implementation for an Issue #2418
2017-02-28 14:00:42 +01:00
Miroslav Stampar
89e9f4939d
Merge pull request #2418 from Ekultek/ip_regex
...
IP address regex updated to not provide a false positive
2017-02-28 14:00:00 +01:00
Ekultek
71984fc452
updated IP address regex as to not provide false positive
2017-02-28 06:35:37 -06:00
Miroslav Stampar
a0a6702a4e
Minor patch (reported via ML)
2017-02-28 13:16:19 +01:00
Miroslav Stampar
b18444f215
Issue #2417 (most probably -> most likely)
2017-02-27 22:14:52 +01:00
Miroslav Stampar
7ea524800a
Taking couple of suggestions from #2417
2017-02-27 22:03:15 +01:00
Miroslav Stampar
7960045cf9
Fixes #2277 and #2300
2017-02-27 13:58:07 +01:00
Miroslav Stampar
d253a97a6f
Merge pull request #2411 from bbbbbrie/master
...
Correct typo in basic.py
2017-02-27 12:55:59 +01:00
Brie Carranza
1475ba441c
Correct typo in basic.py
2017-02-26 09:05:36 -05:00
Miroslav Stampar
b2585cc8ea
Patch for #2410
2017-02-25 07:58:59 +01:00
Miroslav Stampar
7b263327cc
Update for #2410
2017-02-25 07:54:54 +01:00
Miroslav Stampar
cd31bf4ecb
Merge pull request #2410 from qnrq/patch-1
...
Adds option command to api client
2017-02-25 07:47:23 +01:00
Niklas Femerstrand
1b938c758f
Adds option command to api client
2017-02-25 10:24:00 +07:00
Miroslav Stampar
5a08b71999
Minor update
2017-02-23 11:36:37 +01:00
Miroslav Stampar
4b420e7579
Removing Google PageRank as it is dead now
2017-02-23 11:33:39 +01:00
Miroslav Stampar
6b580a682a
Minor update
2017-02-20 10:06:06 +01:00
Miroslav Stampar
d6e7c2acdc
Minor touch
2017-02-19 01:48:12 +01:00
Miroslav Stampar
4d3aa1605c
Merge pull request #2401 from tomahock/master
...
Fix proxyFile regex to properly match an address with a -
2017-02-19 01:31:12 +01:00
Tomahock
7fe1820ce4
Fix proxyFile regex to properly match an address with a -
2017-02-17 23:32:32 +00:00
Miroslav Stampar
98e449e38c
Adding plus2fnconcat tamper script (Issue #2396 )
2017-02-17 10:26:25 +01:00
Miroslav Stampar
9acf122ba6
Patch for an Issue #2396
2017-02-16 16:56:54 +01:00
Miroslav Stampar
2ed144ec85
Patch for wrong encoding reported privately via email
2017-02-16 15:52:07 +01:00
Miroslav Stampar
ec0c103952
Bug fix (reported privately)
2017-02-15 10:30:29 +01:00
Miroslav Stampar
a35d1e5373
Minor patch related to the email from ML
2017-02-14 13:14:35 +01:00
Miroslav Stampar
f5cf22a536
Update for an Issue #2377
2017-02-06 13:57:33 +01:00
Miroslav Stampar
38f16decef
Update for an Issue #2384
2017-02-06 13:28:33 +01:00
Miroslav Stampar
15f86e85b1
Minor update for #2379
2017-02-06 12:03:18 +01:00
Miroslav Stampar
5217efc69b
Fixes #2379
2017-02-06 12:01:46 +01:00
Miroslav Stampar
03bbf552ef
Patch for an Issue #2382
2017-02-06 11:14:45 +01:00
Miroslav Stampar
664684ad8f
Update for #2378
2017-02-03 23:04:38 +01:00
Miroslav Stampar
ddea0bf6e4
Merge pull request #2378 from samogot/patch-1
...
Minor parse-error extension
2017-02-03 22:56:05 +01:00
samogot
1c1f259df4
Update settings.py
...
fix - looking for any tag
2017-02-03 16:50:16 +02:00
samogot
6249823335
Minor parse-error extension
...
parse errors produced by Yii PHP Framework
2017-02-03 16:36:57 +02:00
Miroslav Stampar
bad3f80a1c
Touch update
2017-01-31 14:18:36 +01:00
Miroslav Stampar
529089ba5b
Merge pull request #2374 from anarcoder/space2morecomment
...
New space 2 more comment bypass
2017-01-31 14:16:53 +01:00
Miroslav Stampar
9851a5703a
Fixes #2373
2017-01-31 14:00:12 +01:00
Daniel Almeida
aa9989ff90
[add] new space 2 more comment bypass
2017-01-31 10:50:14 -02:00
Miroslav Stampar
2a3014b606
Fixes #2367
2017-01-24 18:07:06 +01:00
Miroslav Stampar
16d5e22b72
Fixes #2358
2017-01-21 23:58:37 +01:00
Miroslav Stampar
a8a6dce38b
Fixes #2366
2017-01-21 23:09:15 +01:00
Miroslav Stampar
f542e828d2
Fixes #2364
2017-01-20 13:11:12 +01:00
Miroslav Stampar
cf182882b1
Minor update
2017-01-18 10:40:39 +01:00
Miroslav Stampar
2224ac76aa
Merge pull request #2359 from MyKings/master
...
Adding new WAF script(TencentCloud)
2017-01-18 10:36:39 +01:00
Miroslav Stampar
dd5ac6f1e7
Fixes #2357
2017-01-18 10:33:54 +01:00
Miroslav Stampar
1e7a453ff6
Fixes #2356
2017-01-18 10:19:23 +01:00
MyKings
8a84c252be
Adding new WAF script(TencentCloud)
2017-01-18 16:11:03 +08:00
Miroslav Stampar
138aa6db65
Patch for an Issue #2351
2017-01-16 15:23:38 +01:00
Miroslav Stampar
121f0376ea
Implementation for #2351
2017-01-16 14:29:23 +01:00
Miroslav Stampar
dfc684640a
Proper implementation for #2347
2017-01-16 14:01:44 +01:00
Miroslav Stampar
104fbc80af
Patch for #2348
2017-01-16 13:53:46 +01:00
Miroslav Stampar
cadba37059
Proper implementation for #2350
2017-01-16 13:44:46 +01:00
Miroslav Stampar
750d57ec96
Fixed bug reported privately via email
2017-01-13 14:41:41 +01:00
Miroslav Stampar
9a86365d92
Fixes #2333
2017-01-08 01:21:31 +01:00
Miroslav Stampar
f794d9d5a5
Fixes #2328
2017-01-02 15:26:32 +01:00
Miroslav Stampar
c29db43bfa
Minor refactoring
2017-01-02 15:14:59 +01:00
Miroslav Stampar
e0eeed0a96
Minor update
2017-01-02 14:31:19 +01:00
Miroslav Stampar
55272f7a3b
New version preparation
2017-01-02 14:19:18 +01:00
Miroslav Stampar
6ff07f01eb
Fixes #2326
2016-12-31 13:39:22 +01:00
Miroslav Stampar
1c737d7515
Fixes #2322
2016-12-28 22:11:14 +01:00
Miroslav Stampar
2fa5341879
Merge pull request #2323 from CoresecSystems/master
...
Fix the logic used for --param-exclude
2016-12-28 21:44:46 +01:00
Francisco Blas Izquierdo Riera (klondike)
025e9ac5b4
Fix the logic used for --param-exclude
...
The current logic will skip all existing parameters if no param-exclude is defined.
This breaks previous behaviour, makes it harder to use the tool and is quite confusing.
The new logic will always check the parameter is set before running any other checks instead of shortcircuit an empoty(always true) regexp.
2016-12-28 12:25:05 +01:00
Miroslav Stampar
89bbf5284c
Adding new option --param-exclude on private request
2016-12-25 23:16:44 +01:00
Miroslav Stampar
44b00d629d
Fixes #2312
2016-12-21 10:33:35 +01:00
Miroslav Stampar
afc3b30c41
Minor refactoring
2016-12-20 09:56:44 +01:00
Miroslav Stampar
17c556a63d
Minor patches (and one bug from ML)
2016-12-20 09:53:44 +01:00
Miroslav Stampar
edc6f47758
Some refactoring
2016-12-19 23:47:39 +01:00
Miroslav Stampar
bb6e8fd4ce
Minor bug fix (reported privately via email)
2016-12-15 16:09:09 +01:00
Miroslav Stampar
c54c2204a1
Fixes #2303
2016-12-12 10:47:05 +01:00
Miroslav Stampar
f7f33bef9f
Minor patches
2016-12-09 23:19:03 +01:00
Miroslav Stampar
4bd7d81cea
Patches #2300
2016-12-09 23:14:18 +01:00
Miroslav Stampar
f6815df5c3
Fixes #2302
2016-12-09 23:10:14 +01:00
Miroslav Stampar
42cea2e03c
Better git clone (faster; without too much commit history)
2016-12-08 11:04:42 +01:00
Miroslav Stampar
52177065ca
Patch for an Issue #2297
2016-12-06 15:43:09 +01:00
Miroslav Stampar
e74149970b
Minor debug update
2016-12-03 22:06:18 +01:00
Miroslav Stampar
90b0ac37c8
New WAF script (AWS WAF)
2016-12-01 23:09:06 +01:00
Miroslav Stampar
63a74777f2
Minor update
2016-12-01 23:08:49 +01:00
Miroslav Stampar
4ac319b074
Adding new tamper script plus2concat (thank you Luka Pusic)
2016-12-01 22:28:07 +01:00
Miroslav Stampar
2a754eef1c
Adding switch --ignore-redirects (Issue #2286 )
2016-11-25 13:32:28 +01:00
Miroslav Stampar
4e1bdb0c70
Minor update
2016-11-25 12:34:13 +01:00
Miroslav Stampar
c35ba8b226
Fixes #2279
2016-11-17 22:34:10 +01:00
Miroslav Stampar
7e6879ec41
Minor patch for #2272
2016-11-11 13:46:41 +01:00
Miroslav Stampar
ea961678ee
Fixes #2273
2016-11-11 10:28:50 +01:00
Miroslav Stampar
d4414e6631
Minor misspell
2016-11-11 10:21:57 +01:00
Miroslav Stampar
eb098f6527
Fixes #2268
2016-11-09 12:27:10 +01:00
Miroslav Stampar
5772d8904d
Fixes #2266
2016-11-09 12:20:54 +01:00
Miroslav Stampar
7000373c4b
Minor patch
2016-11-09 12:18:15 +01:00
Miroslav Stampar
a60c9b0dcc
Minor patch
2016-11-09 11:29:08 +01:00
Miroslav Stampar
2eb7a1d264
Patch related to the #2265
2016-11-07 23:14:17 +01:00
Miroslav Stampar
13f0949f9e
Another patch for #1596
2016-11-07 09:31:07 +01:00
Miroslav Stampar
076a42cbfe
Patch related to the #1596
2016-11-07 09:28:00 +01:00
Miroslav Stampar
ce19525bc3
Fixes #2262
2016-11-05 22:36:58 +01:00
Miroslav Stampar
6da2e49100
Fixes #2261
2016-11-04 15:04:38 +01:00
Miroslav Stampar
1e44c4d669
Patch related to #2257
2016-11-02 12:04:21 +01:00
Miroslav Stampar
10097dd124
Fixes #2253
2016-10-29 00:13:04 +02:00
Miroslav Stampar
f4e36fc049
Patch for an Issue #2252
2016-10-28 11:52:48 +02:00
Miroslav Stampar
083ce111f0
Minor speed up
2016-10-26 22:33:04 +02:00
Miroslav Stampar
c1d4ab72eb
Merge pull request #2250 from hph86/fix_typos
...
Fix several typos
2016-10-26 22:31:39 +02:00
Hanno Heinrichs
2cc604e356
Fix several typos
2016-10-26 21:41:57 +02:00
Miroslav Stampar
c557637299
Fixes #2248
2016-10-26 08:49:27 +02:00
Miroslav Stampar
044f05e772
Fixes #2246
2016-10-24 23:52:33 +02:00
Miroslav Stampar
6f343080e8
Fixes #2245
2016-10-24 23:33:49 +02:00
Miroslav Stampar
25c34c7728
Fixes #2244
2016-10-24 23:29:18 +02:00
Miroslav Stampar
d2bbe80455
Fixes #2243
2016-10-22 22:07:29 +02:00
Miroslav Stampar
0398cbdc76
Minor refactoring
2016-10-22 21:52:18 +02:00
Miroslav Stampar
e0149e1c5f
Minor update
2016-10-21 13:05:45 +02:00
Miroslav Stampar
98c6d8f582
Merge pull request #2240 from lightos/master
...
Support for timeout param when using Websockets
2016-10-21 13:03:08 +02:00
Miroslav Stampar
d605b3af3c
Revisiting banner xmls (Issue #2239 )
2016-10-21 13:01:28 +02:00
Roberto Salgado
a6cbbc5ea9
Support for timeout param when using Websockets
...
A fix for the timeout parameter being ignored when using Web-sockets.
2016-10-20 12:13:39 -07:00
Miroslav Stampar
5c80e988ba
Fixes #2238
2016-10-20 00:47:53 +02:00
Miroslav Stampar
10ffcb8b00
Fixes #2237
2016-10-20 00:19:16 +02:00
Miroslav Stampar
38d74cf61c
Minor update
2016-10-19 13:07:25 +02:00
Miroslav Stampar
1db6953f08
Proper fix for #2236
2016-10-18 20:17:51 +02:00
Miroslav Stampar
d431c7d155
Fixes #2236
2016-10-18 20:07:19 +02:00
Miroslav Stampar
5ab4d54df0
Minor update of THIRD-PARTY.md
2016-10-18 13:49:29 +02:00
Miroslav Stampar
877d46e9f7
Fixes #2234
2016-10-18 13:46:56 +02:00
Miroslav Stampar
7e69cc112f
Fixes #2235
2016-10-18 13:37:36 +02:00
Miroslav Stampar
5b14eecd25
Bug fix (reconnecting in case of timeouted direct connection)
2016-10-17 22:55:07 +02:00
Miroslav Stampar
24eaf55dc8
Removing bad decision for -d (user should be able to choose)
2016-10-17 22:32:23 +02:00
Miroslav Stampar
6be10b307d
Minor patch
2016-10-17 22:02:41 +02:00
Miroslav Stampar
91ad71b1e0
Minor cosmetics
2016-10-17 12:36:42 +02:00
Miroslav Stampar
d6255de205
Fixes #2231
2016-10-17 12:33:07 +02:00
Miroslav Stampar
c293a6a25a
Fixes #2229 and #2230
2016-10-15 09:53:12 +02:00
Miroslav Stampar
b1175017f9
Minor update regarding to the last commit
2016-10-15 00:54:32 +02:00
Miroslav Stampar
75c9f91f11
Fixes #2226
2016-10-15 00:51:35 +02:00
Miroslav Stampar
9ff2dcf1c1
Fixes #2228
2016-10-15 00:16:53 +02:00
Miroslav Stampar
6c4e9ae427
Updating SocksiPy to PySocks (updated fork)
2016-10-14 23:16:26 +02:00
Miroslav Stampar
748e94dcee
Minor update for #2224
2016-10-13 23:25:46 +02:00
Miroslav Stampar
f389bd71c0
Implementation for an Issue #2224
2016-10-13 23:17:54 +02:00
Miroslav Stampar
1126ff86ce
Fixes #2223
2016-10-13 23:07:11 +02:00
Miroslav Stampar
79377fedab
Minor update
2016-10-13 23:06:04 +02:00
Miroslav Stampar
5d2972f362
Implementation for an Issue #2221
2016-10-11 17:33:36 +02:00
Miroslav Stampar
ae465bbaf8
Minor revert of leftover
2016-10-11 01:09:30 +02:00
Miroslav Stampar
1b95dd2d9d
Fix for a bug reported privately by user (in some cases data has not been retrieved)
2016-10-11 01:07:31 +02:00
Miroslav Stampar
6130185ac6
Minor consistency update with the wiki
2016-10-11 00:35:39 +02:00
Miroslav Stampar
c92fde120d
Implements #2220
2016-10-10 23:27:41 +02:00
Miroslav Stampar
7eab1bcbf9
Automating even more switch --tor
2016-10-10 14:19:44 +02:00
Miroslav Stampar
4c05307357
Disabling socket pre-connect in case of --tor, --proxy and --proxy-file
2016-10-10 01:57:55 +02:00
Miroslav Stampar
0037c28e9e
Preventing obnoxious 'install git' on MacOS
2016-10-10 01:35:22 +02:00
Miroslav Stampar
2b279233b6
Fixes #2219
2016-10-09 14:19:40 +02:00
Miroslav Stampar
b51b80b174
Fix for a privately reported bug
2016-10-08 21:11:43 +02:00
Miroslav Stampar
e4b0ac9ae5
Minor update of common user columns
2016-10-07 14:48:05 +02:00
Miroslav Stampar
7f416846b7
Minor revisit of MsSQL error-based payloads
2016-10-06 23:50:32 +02:00
Miroslav Stampar
5b7254af96
Minor patch
2016-10-06 22:27:29 +02:00
Miroslav Stampar
c83d417298
Fixes #2212
2016-10-05 23:02:20 +02:00
Miroslav Stampar
b42dc6e7a5
Update of Oracle and PostgreSQL system databases/schemas
2016-10-05 17:58:35 +02:00
Miroslav Stampar
8124fe391d
Bug fix for using --search in combination with -D CD
2016-10-05 17:43:57 +02:00
Miroslav Stampar
833ca4b640
Minor refactoring
2016-10-05 17:41:02 +02:00
Miroslav Stampar
3b244858f8
Adding performance_schema as one more of MySQL's system database
2016-10-05 17:33:24 +02:00
Miroslav Stampar
6107696e25
Minor patch (--help should display basic help)
2016-10-05 17:01:58 +02:00
Miroslav Stampar
af1c9c7fb2
Related to the last commit
2016-10-04 23:48:09 +02:00
Miroslav Stampar
06b54ab134
Better choice of used table (INFORMATION_SCHEMA.CHARACTER_SETS can also be found in MsSQL and PgSQL; mysql.db can have permission problems)
2016-10-04 23:43:00 +02:00
Miroslav Stampar
fee5c7bd7c
Adding two new payloads and minor cosmetics
2016-10-04 23:39:18 +02:00
Miroslav Stampar
fb8afc6add
Adding a new payload (Oracle boolean based on error response)
2016-10-04 22:12:00 +02:00
Miroslav Stampar
6c372a09bd
Minor update
2016-10-04 11:55:16 +02:00
Miroslav Stampar
171cf6f54d
Minor fine tuning for SQLi heuristic check
2016-10-04 11:32:06 +02:00
Miroslav Stampar
029bb5554d
Minor cleanup of user-agents
2016-10-04 10:48:10 +02:00
Miroslav Stampar
c69cb79d66
Fixes #2208
2016-10-04 10:39:28 +02:00
Miroslav Stampar
dc8301689e
Implementation for an Issue #2204
2016-10-02 11:13:40 +02:00
Miroslav Stampar
d8dd37510c
Fixes #2202
2016-10-01 21:02:40 +02:00
Miroslav Stampar
d1680b04f3
Minor code consistency update
2016-09-29 21:26:47 +02:00
Miroslav Stampar
102d4b4119
Bug fix for uploading files in case of web subdirectories
2016-09-29 21:14:28 +02:00
Miroslav Stampar
b3b49b3492
Minor patch for --parse-errors
2016-09-29 18:07:00 +02:00
Miroslav Stampar
7a89433251
Minor patch
2016-09-29 18:02:20 +02:00
Miroslav Stampar
ced6711128
Playing a bit with logo
2016-09-29 15:59:28 +02:00
Miroslav Stampar
bdf76f8d4d
Revisiting user-agents (newer versions of mainstream browsers)
2016-09-29 15:21:32 +02:00
Miroslav Stampar
571ae174bd
Minor language update
2016-09-29 14:55:43 +02:00
Miroslav Stampar
332726356c
Minor language update
2016-09-29 14:03:46 +02:00
Miroslav Stampar
4ea9d3b884
Replacing generic concatenation || with CONCAT (far better choice)
2016-09-29 13:35:16 +02:00
Miroslav Stampar
3409953538
Revisiting default level 1 payloads (MySQL stacked queries are as frequent as double rainbows)
2016-09-29 12:59:51 +02:00
Miroslav Stampar
3b3ab072e6
Adding short option(s) for setting verbosity (e.g. -vvv)
2016-09-29 11:19:25 +02:00
Miroslav Stampar
fef407e09c
Making HTTP requests up to 20% smaller (fine tuning the request headers)
2016-09-29 10:44:00 +02:00
Miroslav Stampar
5afccce3c6
Minor patch
2016-09-28 16:56:47 +02:00
Miroslav Stampar
e439095593
Bug fix for MySQL's --os-pwn
2016-09-28 15:39:34 +02:00
Miroslav Stampar
e77126e847
Removing obsolete functionality
2016-09-28 15:00:26 +02:00
Miroslav Stampar
3ef01f0e31
Minor update
2016-09-28 14:48:33 +02:00
Miroslav Stampar
d36b5c0a4b
Adding time-based blind (heavy query) payloads for Informix (Issue #552 )
2016-09-28 10:30:09 +02:00
Miroslav Stampar
e5a758bdf4
Fixes #2192
2016-09-28 09:55:14 +02:00
Miroslav Stampar
617509869d
Minor patch for Informix --parse-errors
2016-09-27 14:58:10 +02:00
Miroslav Stampar
5079c42788
Adding Informix parameter replacement payloads (Issue #552 )
2016-09-27 14:39:17 +02:00
Miroslav Stampar
bc7ab01066
Bug fix for generic parameter replacement (CASE)
2016-09-27 14:29:18 +02:00
Miroslav Stampar
212c1ec1f2
Couple of fixes and some testing stuff
2016-09-27 14:03:59 +02:00
Miroslav Stampar
381deb68ff
Implementation for an Issue #2137
2016-09-27 13:26:11 +02:00
Miroslav Stampar
ba0facb5eb
Removal of unused imports
2016-09-27 11:23:31 +02:00
Miroslav Stampar
7151df16f6
Adding extra validation step in case of boolean-based blind (e.g. if unexpected 500 occurs)
2016-09-27 11:21:12 +02:00
Miroslav Stampar
8994bf2dba
Further dealing with time-based SQLi (Issue #1973 )
2016-09-27 10:32:22 +02:00
Miroslav Stampar
09617c8243
Introducing extra validation property in case of time-based SQLi (HTTP code) - Issue #1973
2016-09-27 10:20:36 +02:00
Miroslav Stampar
556b4d289e
Minor cosmetic patch (removing multiple same content '...appears...' messages)
2016-09-26 17:02:40 +02:00
Miroslav Stampar
978f56ad10
One more commit for #552 (--passwords)
2016-09-26 16:38:03 +02:00
Miroslav Stampar
aa0b97b562
Support for Informix --roles/--privileges (Issue #552 )
2016-09-26 14:20:04 +02:00
Miroslav Stampar
df645d7d3d
Update for column types (Issue #552 )
2016-09-23 18:03:31 +02:00
Miroslav Stampar
035137ef4e
Bug fix in detection engine (abstract URI header sometimes caused problems - e.g. when automatic --string used)
2016-09-23 17:38:14 +02:00
Miroslav Stampar
484d9a4825
Implementation of --dump for Informix (Issue #552 )
2016-09-23 17:21:48 +02:00
Miroslav Stampar
65c305cff0
Fixes #2174
2016-09-23 15:41:12 +02:00
Miroslav Stampar
9a5fc5ccf4
New auxiliary (extra) file (for administration purposes)
2016-09-23 13:57:18 +02:00
Miroslav Stampar
51a1973224
Stripping PostgreSQL .so files for size issues (Issue #2173 )
2016-09-23 13:52:57 +02:00
Miroslav Stampar
2f2a63334a
Minor cleanup
2016-09-23 13:39:27 +02:00
Miroslav Stampar
23afeb4c7a
Fixes #2176
2016-09-23 13:37:44 +02:00
Miroslav Stampar
b387fb219d
Fixes #2175
2016-09-23 12:45:06 +02:00
Miroslav Stampar
1b48ff223d
Adding initial support for Informix (Issue #552 )
2016-09-23 12:33:27 +02:00
Miroslav Stampar
640e605412
More CTF friendly (common column and table name flag :)
2016-09-23 12:31:28 +02:00
Miroslav Stampar
e10bb42597
Minor tweak
2016-09-22 10:22:48 +02:00
Miroslav Stampar
9902018cab
Implementation for an Issue #2172
2016-09-21 15:45:55 +02:00
Miroslav Stampar
56a918c408
Minor refactoring
2016-09-20 10:03:00 +02:00
Miroslav Stampar
bcd62ecc5b
Minor optimization (avoiding unnecessary deepcopies)
2016-09-20 09:56:08 +02:00
Miroslav Stampar
e519484230
Patching live-testing
2016-09-19 15:51:28 +02:00
Miroslav Stampar
a2c8f1deb1
Update PgSQL fingerprinting payloads
2016-09-19 14:23:51 +02:00
Miroslav Stampar
12dc53f687
Minor update
2016-09-19 13:54:06 +02:00
Miroslav Stampar
b3b5bd267d
Adding new tamper script (on request from @MilanGabor)
2016-09-15 17:59:01 +02:00
Miroslav Stampar
edcfffc279
Merge pull request #2170 from ClementNotin/ClementNotin-patch-netscaler.py
...
Fix "or-assign" for return value in netscaler.py
2016-09-15 17:29:31 +02:00
Clément Notin
3bbfd0665c
Fix "or-assign" for return value in netscaler.py
2016-09-15 16:56:49 +02:00
Miroslav Stampar
921a53e314
Patch for counter in --smoke-test
2016-09-09 14:59:22 +02:00
Miroslav Stampar
32dd4a938c
Minor patch of message
2016-09-09 11:37:16 +02:00
Miroslav Stampar
9930f1b55b
Speed optimization(s)
2016-09-09 11:06:38 +02:00
Miroslav Stampar
8581d9e2ca
Minor improvement of SELECT_FROM_TABLE_REGEX
2016-09-09 09:45:48 +02:00
Miroslav Stampar
1a613ed9a8
Minor update
2016-09-08 14:08:14 +02:00
Miroslav Stampar
78e398d9c4
Fixes #2136
2016-09-06 15:03:17 +02:00
Miroslav Stampar
e3c3c2c185
Fixes #2148
2016-09-06 14:25:29 +02:00
Miroslav Stampar
4e36bbaff9
Update related to the last commit
2016-09-04 03:09:28 +02:00
Miroslav Stampar
603e9739ae
Fixes #2146
2016-09-04 01:33:52 +02:00
Miroslav Stampar
6b91b7b7fa
Minor cosmetics
2016-09-02 16:10:11 +02:00
Miroslav Stampar
2e62fda57d
Minor update
2016-09-02 15:55:33 +02:00
Miroslav Stampar
5ad27264a2
Patches #2143
2016-09-02 15:52:07 +02:00
Miroslav Stampar
c4d8cab50c
Version string bug fix
2016-09-02 14:25:56 +02:00
Miroslav Stampar
577e346774
Fixes #2144
2016-09-02 14:20:17 +02:00
Miroslav Stampar
81c6aad129
Merge pull request #2138 from TrinTragula/Italian_Translation
...
Translated README-it-IT in order to make it even more italian-friendly.
2016-09-01 09:43:52 +02:00
TrinTragula
775325556e
Translated in order to make it even more italian-friendly
2016-08-30 07:26:28 -04:00
Miroslav Stampar
375abd50ee
Minor update for #2134
2016-08-30 12:36:32 +02:00
Miroslav Stampar
e718e2732e
Merge pull request #2134 from TrinTragula/Italian_Translation
...
Added Italian version of README
2016-08-30 12:35:14 +02:00
TrinTragula
8c8764368f
Added Italian version of README and added link to it on the english version
2016-08-27 20:32:13 -04:00
Miroslav Stampar
4a815ab56f
Patch for an Issue #1250
2016-08-27 23:54:09 +02:00
Miroslav Stampar
6564adc984
Minor patch for buffered write into checksum.md5
2016-08-27 23:34:12 +02:00
Miroslav Stampar
ad5b8017f5
Minor refactoring
2016-08-26 12:28:35 +02:00
Miroslav Stampar
72e5a79288
Fixes #2106
2016-08-19 11:07:42 +02:00
Miroslav Stampar
63f4b3462f
Fixes #2105
2016-08-15 18:35:04 +02:00
Miroslav Stampar
a45a90df94
Adding new WAF script (Yunsuo)
2016-08-12 14:32:03 +02:00
Miroslav Stampar
ec1ac81e0a
Minor refactoring
2016-08-08 16:08:16 +02:00
Miroslav Stampar
6ba46bf7cf
Update for #2086 (lowercasing only the command)
2016-08-08 15:55:39 +02:00
Miroslav Stampar
a1f85df12b
Merge pull request #2086 from deadworoz/patch-1
...
Converting a command to lowercase breaks a case-sensitive URL
2016-08-08 15:48:41 +02:00
deadworoz
9c2c3894d6
Converting a command to lowercase breaks a case-sensitive URL
...
To reproduce the bug:
1. Start the server: ./sqlmapapi.py -s
2. Start the client: ./sqlmapapi.py -c
3. Add a new task with a case-sensitive URL: new -u "http://vbox.lc/bWAPP/sqli_4.php?title=iron+man&action=search "
4. Check the log:
...
"message": "testing connection to the target URL"
...
"message": "page not found (404)"
...
"message": "HTTP error codes detected during run:\n404 (Not Found) - 1 times"
5. Check that sqlmap.py correcty work with same parameters: ./sqlmap.py -u "http://vbox.lc/bWAPP/sqli_4.php?title=iron+man&action=search "
[INFO] testing connection to the target URL
[INFO] checking if the target is protected by some kind of WAF/IPS/IDS
2016-08-08 14:48:25 +04:00
Miroslav Stampar
b92fc840fe
Adding pypi script to the repository
2016-08-02 13:21:05 +02:00
Miroslav Stampar
ef79bbf7d2
Minor patch
2016-08-02 12:38:57 +02:00
Miroslav Stampar
fba1199cd2
Minor consistency update
2016-08-02 12:05:39 +02:00
Miroslav Stampar
4022a68523
Removing last debug commit
2016-08-02 12:01:49 +02:00
Miroslav Stampar
67bc3ed359
Trying out the last commit
2016-08-02 12:01:02 +02:00
Miroslav Stampar
a0ddd99087
Minor update for automatic PyPI packaging
2016-08-02 12:00:21 +02:00
Miroslav Stampar
2a7ef58c9f
Minor refactoring
2016-08-02 11:55:11 +02:00
Miroslav Stampar
35010006a1
Some cosmetic changes
2016-08-02 11:50:42 +02:00
Miroslav Stampar
acfe788c95
Preparing for #1250
2016-08-02 00:17:59 +02:00
Miroslav Stampar
5ccb73a1ee
Minor patch for Python3 check
2016-07-29 15:30:59 +02:00
Miroslav Stampar
6ac5b6b759
Minor refactoring
2016-07-28 17:04:15 +02:00
Miroslav Stampar
d82f20abc4
Fixes #2068
2016-07-28 17:02:27 +02:00
Miroslav Stampar
10eafa35fd
Adding CloudFlare CAPTCHA warning
2016-07-23 23:02:15 +02:00
Miroslav Stampar
9105f259cd
Fixes #2060 (ParseError has been added in Python 2.7)
2016-07-23 15:27:25 +02:00
Miroslav Stampar
7cca56edfa
Fixes #2052
2016-07-21 09:38:52 +02:00
Miroslav Stampar
e21d751834
Fixes #2049
2016-07-20 20:04:44 +02:00
Miroslav Stampar
ebb73b71fa
Fixes #2045
2016-07-20 16:49:27 +02:00
Miroslav Stampar
1ca633ae64
Fixes #2031
2016-07-17 23:30:40 +02:00
Miroslav Stampar
3e22cbfed7
Minor update
2016-07-17 00:34:14 +02:00
Miroslav Stampar
c7f615f707
Renaming payload files (consistency with the rest of the project)
2016-07-17 00:21:16 +02:00
Miroslav Stampar
b83ee92cd1
Minor modification
2016-07-17 00:09:09 +02:00
Miroslav Stampar
571d669a09
Minor modification
2016-07-17 00:07:58 +02:00
Miroslav Stampar
e485531b71
Adding integrity checks in case of unhandled exceptions
2016-07-17 00:04:30 +02:00
Miroslav Stampar
7427b554e3
Adding support for integrity checks
2016-07-16 23:25:13 +02:00
Miroslav Stampar
1a818ceccd
Adding error message regarding #2030
2016-07-16 22:47:16 +02:00
Miroslav Stampar
7fea8d608e
Fixes #2028
2016-07-16 22:42:15 +02:00
Miroslav Stampar
1e6191e3b1
Fixes #2026
2016-07-16 15:51:09 +02:00
Miroslav Stampar
c10b2825d7
Patch for --os-shell against Windows/MySQL where resulting \r caused trouble
2016-07-15 11:56:51 +02:00
Miroslav Stampar
c200b2cb19
Another fix (related to the last commit)
2016-07-15 11:45:59 +02:00
Miroslav Stampar
071f4c8a2b
Bug fix (reported privately) - better parsing of file paths (especially for Windows cases)
2016-07-15 11:13:47 +02:00
Miroslav Stampar
5097a2c79e
Less timeout error messages (because of server dropping of non-active connections)
2016-07-15 00:33:33 +02:00
Miroslav Stampar
bce9db1af5
Adding support for --columns too (Issue #2025 )
2016-07-15 00:10:41 +02:00
Miroslav Stampar
ca67456dbe
Removing a debugging leftover (Issue #2025 )
2016-07-14 23:39:44 +02:00
Miroslav Stampar
6df4d73b09
Implementation for an Issue #2025
2016-07-14 23:18:28 +02:00
Miroslav Stampar
2aaa486f7a
Minor code style update
2016-07-13 14:09:33 +02:00
Miroslav Stampar
47ba7d4705
Minor update
2016-07-07 10:37:00 +02:00
Miroslav Stampar
6a8bfd5fd8
Update for an Issue #2011
2016-07-07 09:20:44 +02:00
Miroslav Stampar
1df94747e1
Merge pull request #2011 from guinslym/fr-FR
...
Added a French translation fr-Fr
2016-07-07 09:17:42 +02:00
Guinsly Mondesir
4092c701fe
french translation
2016-07-06 21:05:38 -04:00
Guinsly Mondesir
4939bd49b0
french translation
2016-07-06 21:01:48 -04:00
Guinsly Mondesir
c6fb3d35d8
french translation
2016-07-06 21:00:13 -04:00
Guinsly Mondesir
aad0bd8705
french translation
2016-07-06 20:58:29 -04:00
Guinsly Mondesir
b69f635a3f
french translation
2016-07-06 20:56:36 -04:00
Guinsly Mondesir
eeae696b1b
french translation
2016-07-06 20:54:16 -04:00
Guinsly Mondesir
e1c8bc0e01
french translation
2016-07-06 20:53:48 -04:00
Guinsly Mondesir
4b0acee585
french translation
2016-07-06 20:52:03 -04:00
Guinsly Mondesir
d74612eb4c
french translation
2016-07-06 20:50:31 -04:00
Guinsly Mondesir
88c33974ac
french translation
2016-07-06 20:48:57 -04:00
Guinsly Mondesir
e5d7bfe453
french translation
2016-07-06 20:47:35 -04:00
Guinsly Mondesir
99d23237b4
french translation
2016-07-06 20:44:56 -04:00
Guinsly Mondesir
08d750197c
french translation
2016-07-06 20:44:26 -04:00
Guinsly Mondesir
d35bdf6eaa
french translation
2016-07-06 20:43:31 -04:00
Guinsly Mondesir
d332e00eb0
french translation
2016-07-06 20:42:55 -04:00
Guinsly Mondesir
9d5499597f
french translation
2016-07-06 20:42:24 -04:00
Guinsly Mondesir
c0f8bbbc72
french translation
2016-07-06 20:41:39 -04:00
Guinsly Mondesir
1684d60782
french translation version 2.0
2016-07-06 20:40:25 -04:00
Guinsly Mondesir
af6a977c9a
moving the French translation to another folder
2016-07-06 19:45:50 -04:00
Guinsly Mondesir
f20263f235
creating a base file for fr tranlsation
2016-07-06 19:44:37 -04:00
Miroslav Stampar
2e42afea6f
Update of sucury WAF script
2016-07-06 23:43:21 +02:00
Miroslav Stampar
292a28131d
Minor updates
2016-07-06 23:43:10 +02:00
Miroslav Stampar
2e775fbb75
(e.g.) ASPx MsSQL Chinese exception messages don't start with 'Exception: string'
2016-07-06 14:06:18 +02:00
Miroslav Stampar
e1d7641b8a
Good for different generic OleDB-alike connectors
2016-07-06 13:48:35 +02:00
Miroslav Stampar
6b0951d1ee
Switching default Tor type to SOCKS5 (various bundles are discontinued)
2016-07-06 13:30:46 +02:00
Miroslav Stampar
db1fc621b5
Update for SonicWALL WAF script; lesser false positives with ModSecurity WAF script
2016-07-06 13:19:51 +02:00
Miroslav Stampar
9351756c36
Minor update of format exception strings
2016-07-05 16:02:34 +02:00
Miroslav Stampar
63b645c64c
Removing a debugging leftover
2016-07-05 09:32:30 +02:00
Miroslav Stampar
7ad49f4185
Less problematic regexes for MsSQL errors
2016-07-05 09:32:08 +02:00
Miroslav Stampar
d9315830f9
Less problematic regex for MsSQL errors
2016-07-05 09:20:04 +02:00
Miroslav Stampar
2e2c62b6a7
More error regexes
2016-07-04 17:24:17 +02:00
Miroslav Stampar
53289b0234
Some more Informix error regexes
2016-07-04 10:03:36 +02:00
Miroslav Stampar
dd082ef79d
Minor update (new error regex for Informix)
2016-07-04 09:49:18 +02:00
Miroslav Stampar
2c968f9a35
Closes #2007
2016-07-04 09:12:30 +02:00
Miroslav Stampar
74d0315fef
Update related to the last commit
2016-07-03 02:14:23 +02:00
Miroslav Stampar
ae98159130
Automatic monthly tagging
2016-07-03 02:03:30 +02:00
Miroslav Stampar
3a9e36c52b
Reintroducing stacked queries removed in 79d08906a4 (good for WAF bypass)
2016-07-03 02:03:30 +02:00
Miroslav Stampar
cb43c03712
Definite patch for MemoryError(s) ( fixes #1991 )
2016-06-30 14:57:56 +02:00
Miroslav Stampar
65a0f15f69
Minor update (error regex for PHP's sqlsrv module)
2016-06-28 15:13:37 +02:00
Miroslav Stampar
98b77d32cc
Minor update
2016-06-27 11:16:41 +02:00
Miroslav Stampar
86a3569ccb
New WAF script (SonicWALL)
2016-06-26 16:42:05 +02:00
Miroslav Stampar
17fca351d3
Minor update
2016-06-26 16:26:13 +02:00
Miroslav Stampar
2614e7bec1
Minor update
2016-06-26 16:23:39 +02:00
Miroslav Stampar
832c6e806f
Revert of last commit
2016-06-26 15:59:35 +02:00
Miroslav Stampar
7b334b0808
'Conversion failed' happens in regular SQLi on MsSQL
2016-06-26 15:57:11 +02:00
Miroslav Stampar
aa9151785e
Minor update
2016-06-26 15:37:30 +02:00
Miroslav Stampar
6bdef1b7da
Minor update
2016-06-26 01:46:49 +02:00
Miroslav Stampar
8b4367d354
Revert of last commit
2016-06-26 01:42:21 +02:00
Miroslav Stampar
0a9d69a7d0
Minor patch
2016-06-26 01:10:47 +02:00
Miroslav Stampar
a4b60dc00f
New error regex for MsSQL
2016-06-26 00:40:54 +02:00
Miroslav Stampar
f91ae32284
Minor update (to not confuse S3 vs Cloudfront)
2016-06-24 13:39:13 +02:00
Miroslav Stampar
53fc9d6720
Fixes #1990
2016-06-24 13:31:19 +02:00
Miroslav Stampar
0b31568306
Minor update
2016-06-24 13:28:08 +02:00
Miroslav Stampar
e9407cf791
Cleaning some garbage boundaries (it doesn't make any sense to use %00 as prefix)
2016-06-23 22:57:59 +02:00
Miroslav Stampar
0175acd028
Bug fix (in some cases lack of warning message for SQLi appearing)
2016-06-23 17:52:37 +02:00
Miroslav Stampar
733a32de32
Minor patch
2016-06-23 12:09:51 +02:00
Miroslav Stampar
1b863ecf93
Far better detection of SecureIIS (WAF)
2016-06-23 12:03:05 +02:00
Miroslav Stampar
ec06037335
Update of bigip waf script
2016-06-23 11:41:49 +02:00
Miroslav Stampar
0cdb62a1b5
Adding new waf script (armor)
2016-06-23 11:15:31 +02:00
Miroslav Stampar
99454198b8
Minor refactoring
2016-06-20 10:01:57 +02:00
Miroslav Stampar
dd6287ace8
Fixes #1972
2016-06-20 09:59:50 +02:00
Miroslav Stampar
786460e3b4
Minor just in case patch
2016-06-19 17:44:47 +02:00
Miroslav Stampar
419cf979f1
Showing again the 'shutting down at ...' message
2016-06-19 17:17:01 +02:00
Miroslav Stampar
30be875304
Patch for an Issue #1968
2016-06-18 01:21:57 +02:00
Miroslav Stampar
7d011bc811
Fixes #1964
2016-06-17 17:07:44 +02:00
Miroslav Stampar
b2c4a3b247
Fixes #1960
2016-06-17 16:54:23 +02:00
Miroslav Stampar
9d9592a69b
Fixes #1963
2016-06-17 16:51:23 +02:00
Miroslav Stampar
cb42294a7e
Minor message update
2016-06-15 07:57:10 +02:00
Miroslav Stampar
146762c109
Minor update
2016-06-15 07:54:47 +02:00
Miroslav Stampar
494b9d1586
Fixes #1943
2016-06-13 15:30:38 +02:00
Miroslav Stampar
2e95fdb52d
Fixes #1947
2016-06-13 14:50:44 +02:00
Miroslav Stampar
46736cac7b
Fixes #1931
2016-06-10 18:41:41 +02:00
Miroslav Stampar
041213f22d
Fixes #1935
2016-06-10 18:18:48 +02:00
Miroslav Stampar
8ca45c5678
Fixes #1936
2016-06-10 18:02:24 +02:00
Miroslav Stampar
c6eec8db97
Fixes #1938
2016-06-10 17:52:22 +02:00
Miroslav Stampar
98fdc493f4
Proper patch for #1923 ( Fixes #1940 , #1941 )
2016-06-10 17:42:11 +02:00
Miroslav Stampar
91372bff87
Fixes #1932
2016-06-08 08:20:54 +02:00
Miroslav Stampar
7fb9db42a7
Performing a backup of old dump file (Issue #841 )
2016-06-05 12:37:19 +02:00
Miroslav Stampar
82382957f9
Minor refactoring
2016-06-05 12:25:42 +02:00
Miroslav Stampar
f034122bd0
Fixes #1920
2016-06-05 12:14:01 +02:00
Miroslav Stampar
0df2456f34
Fixes #1923
2016-06-03 16:06:29 +02:00
Miroslav Stampar
78fdb27a0b
More improvements
2016-06-03 15:51:52 +02:00
Miroslav Stampar
350baf0a0a
Minor update
2016-06-03 14:29:32 +02:00
Miroslav Stampar
9886b646eb
Proper update regarding the last commit
2016-06-03 14:18:28 +02:00
Miroslav Stampar
c5197b99a0
Minor patch and minor improvement
2016-06-03 13:59:32 +02:00
Miroslav Stampar
cc313280af
Payload that never ever worked (now fixed)
2016-06-03 13:16:00 +02:00
Miroslav Stampar
f06ff42c58
This never worked. Not sure who incorporated it (WAITFOR DELAY can't go to SELECT/CASE)
2016-06-03 10:42:57 +02:00
Miroslav Stampar
4bc1cf4518
Vastly better patch for MsSQL payloads
2016-06-03 10:29:04 +02:00
Miroslav Stampar
0e65043c84
Minor adjustment
2016-06-03 09:48:49 +02:00
Miroslav Stampar
d7d565415a
Patch for MySQL fingerprinting
2016-06-03 02:31:31 +02:00
Miroslav Stampar
0986ec8948
Update for Oracle fingerprinting
2016-06-03 02:27:59 +02:00
Miroslav Stampar
50bced511f
Adding support for fingerprinting MsSQL 2014 and 2016
2016-06-03 02:24:19 +02:00
Miroslav Stampar
e275e8c0b0
Fixes #1921
2016-06-03 02:02:11 +02:00
Miroslav Stampar
77dea38ac1
Fixes #1918
2016-06-03 00:37:18 +02:00
Miroslav Stampar
7dc2ec5fd8
Minor touch
2016-06-01 20:42:09 +02:00
Miroslav Stampar
4bf2e3b139
Minor update
2016-06-01 20:37:05 +02:00
Miroslav Stampar
8114c14755
Removing leftover
2016-06-01 16:32:22 +02:00
Miroslav Stampar
ec8cf6aadc
Adding support for detecting CAPTCHA
2016-06-01 15:48:04 +02:00
Miroslav Stampar
d326965966
Reordering MySQL's error-based payloads (BIGINT and EXP have crazy bigger chunk lenghts)
2016-06-01 14:12:22 +02:00
Miroslav Stampar
030df0353d
Removing ugly legacy code (e.g. showing MySQL 5.0 when it is e.g. '5.7.8')
2016-06-01 13:47:20 +02:00
Miroslav Stampar
5038d7a70a
Removing ugly boolean check results (0 or 1) in output of UNION and ERROR SQLi
2016-06-01 13:39:40 +02:00
Miroslav Stampar
f0b8fbb7fd
Implemented support for JSON_KEYS error-based SQLi (and tons of fixes for MySQL 'ORDER BY,GROUP BY' payloads)
2016-06-01 13:23:41 +02:00
Miroslav Stampar
5810c2b199
Minor patch
2016-06-01 11:30:27 +02:00
Miroslav Stampar
77f0b5dfa8
Fixes #1919
2016-06-01 10:56:42 +02:00
Miroslav Stampar
b0ea74dc63
Minor warning message update
2016-06-01 10:53:32 +02:00
Miroslav Stampar
0c07c8942c
Automatic monthly tagging
2016-06-01 10:44:08 +02:00
Miroslav Stampar
7d1bdb35ca
Update of parsed versions
2016-06-01 10:44:08 +02:00
Miroslav Stampar
e823889819
Update for JSP exceptions
2016-05-31 15:35:10 +02:00
Miroslav Stampar
680aedaefc
Adding option --tmp-dir
2016-05-31 14:55:56 +02:00
Miroslav Stampar
afdca09ced
Minor patches (proper user warnings in case of output directory permissions)
2016-05-31 14:05:35 +02:00
Miroslav Stampar
ac89ee71c3
Minor improvement
2016-05-31 13:29:43 +02:00
Miroslav Stampar
af7c8cff92
Bug fix (previously removing temporary directory even if it is needed afterwards)
2016-05-31 13:21:08 +02:00
Miroslav Stampar
26d4dec5fb
Minor refactoring
2016-05-31 13:02:26 +02:00
Miroslav Stampar
cf31d12528
Adding support for python's cgitb tracebacks
2016-05-31 12:33:56 +02:00
Miroslav Stampar
b4c730f8c0
Minor refactoring
2016-05-31 12:23:59 +02:00
Miroslav Stampar
fba1720b31
Minor patch
2016-05-31 11:16:13 +02:00
Miroslav Stampar
9fad72f28b
Adding support for MsAccess usage of parsed FROM table names (e.g. in case of ColdFusion)
2016-05-31 11:08:23 +02:00
Miroslav Stampar
1782bf8e64
Adding support for parsing ODBC/JDBC error messages
2016-05-31 10:49:34 +02:00
Miroslav Stampar
2d59a10515
Better patch than last commit
2016-05-31 10:25:01 +02:00
Miroslav Stampar
21a25c4f00
Bug for fix comments in case of MsAccess
2016-05-31 10:24:13 +02:00
Miroslav Stampar
6b5c16c22c
Minor update for ColdFusion error messages
2016-05-31 09:54:14 +02:00
Miroslav Stampar
2c6621c26a
Minor upgrade for WAF/IDS/IPS detection
2016-05-31 09:49:50 +02:00
Miroslav Stampar
f0500b1d2f
Minor update for ColdFusion path regexes
2016-05-31 09:35:58 +02:00
Miroslav Stampar
6a033bb58c
Minor update for ColdFusion type casting
2016-05-31 09:31:32 +02:00
Miroslav Stampar
2fa4b22645
Patch for URL encoding cookie values (asking the user to choose)
2016-05-30 17:47:08 +02:00
Miroslav Stampar
229d3a7dd0
Patch for cases when error page looks more like original, than the False one does
2016-05-30 16:46:23 +02:00
Miroslav Stampar
b965e5bf1c
Minor refactoring
2016-05-30 16:06:39 +02:00
Miroslav Stampar
3bd74c5351
Minor patch
2016-05-30 15:20:21 +02:00
Miroslav Stampar
55624ec1a2
Minor message update
2016-05-30 14:40:22 +02:00
Miroslav Stampar
6885afe8c3
Minor update for requestvalidationmode.py waf script
2016-05-30 14:26:55 +02:00
Miroslav Stampar
acc1277246
Minor update
2016-05-30 14:13:57 +02:00
Miroslav Stampar
935cb9c8cb
Patch for a custom header cookie urlencoding
2016-05-30 14:09:53 +02:00
Miroslav Stampar
17a4ddad63
Fixes #1916
2016-05-30 13:10:25 +02:00
Miroslav Stampar
5264671f5b
Dump formatting patch for MsAccess
2016-05-30 12:03:33 +02:00
Miroslav Stampar
b4ebbae354
New payload(s)
2016-05-30 11:25:24 +02:00
Miroslav Stampar
510197c39e
Minor text update
2016-05-30 10:52:30 +02:00
Miroslav Stampar
b6a4bd91fe
Minor text update
2016-05-30 10:51:35 +02:00
Miroslav Stampar
83b82a5e98
Bug fix (wrong handler used in case of DBMS resolution)
2016-05-30 10:32:49 +02:00
Miroslav Stampar
0b1efc0759
Minor update (for newer versions of MsSQL)
2016-05-30 01:38:34 +02:00
Miroslav Stampar
2b506d744d
Minor update
2016-05-30 01:29:40 +02:00
Miroslav Stampar
79d08906a4
Cleaning some redundant payload(s)
2016-05-27 23:59:48 +02:00
Miroslav Stampar
d27b33e26c
Update README.md
2016-05-27 23:03:59 +02:00
Miroslav Stampar
73d86f0fdd
Merge pull request #1898 from kuma-guy/ja-JP
...
Adding translation for README in Japanese(JP).
2016-05-27 23:02:11 +02:00
Miroslav Stampar
6327063bd0
Minor patch
2016-05-27 16:43:01 +02:00
Miroslav Stampar
69fd900108
Adding waf script for detection of generic/unknown
2016-05-27 16:34:41 +02:00
Miroslav Stampar
f9d01f682b
Cloudflare has tons of HTTP error codes while detecting SQLi
2016-05-27 15:58:16 +02:00
Miroslav Stampar
d7d3db415b
Minor update
2016-05-27 15:32:30 +02:00
Miroslav Stampar
608f141f52
New waf scripts
2016-05-27 15:22:08 +02:00
Miroslav Stampar
31850e4544
Minor bug fixes
2016-05-27 13:58:18 +02:00
Miroslav Stampar
de9f23939f
Major bug fix in WAF/IDS/IPS detection (question 'do you want..to try to detect backend WAF/IPS/IDS' never worked)
2016-05-27 13:41:03 +02:00
Miroslav Stampar
154ed2c4e2
Minor patch
2016-05-27 13:33:14 +02:00
Miroslav Stampar
89dfe4e1ac
Adding wallarm WAF script (and couple of other WAF script updates)
2016-05-27 11:58:18 +02:00
Miroslav Stampar
b41b07ddd8
Updates for 360 and jiasule WAF scripts
2016-05-27 11:02:05 +02:00
Miroslav Stampar
e36fc02282
Adding sophos WAF script
2016-05-27 10:17:42 +02:00
Miroslav Stampar
49b41c1eca
Minor update for cloudflare waf script
2016-05-27 09:43:54 +02:00
Miroslav Stampar
4cd9fdb7df
Minor update for F5 waf script
2016-05-27 09:27:45 +02:00
Miroslav Stampar
5aab2d8fb5
Update for Akamai Kona WAF script
2016-05-27 09:22:39 +02:00
Miroslav Stampar
210b65c02d
Couple of fixes for --identify-waf
2016-05-27 02:24:59 +02:00
Miroslav Stampar
7a2ac23f0b
Adding new waf script (sitelock)
2016-05-27 02:13:01 +02:00
Miroslav Stampar
e435fb2e9e
Adding new waf script (comodo)
2016-05-27 01:23:20 +02:00
Miroslav Stampar
6892c94595
Minor update
2016-05-27 01:10:37 +02:00
Miroslav Stampar
831c960216
Update for an Issue #1899
2016-05-26 16:47:38 +02:00
Miroslav Stampar
43af2a4aee
Fixes #1899
2016-05-26 16:08:59 +02:00
Shingo Kumagai
190819e85d
Adding translation for README in Japanese(JP).
2016-05-26 09:37:45 +09:00
Miroslav Stampar
1de6996c26
Fixes #1893
2016-05-25 15:43:39 +02:00
Miroslav Stampar
304f2ed308
Minor language patch
2016-05-25 15:32:17 +02:00
Miroslav Stampar
148b35da4f
Better extraction of absolute file paths
2016-05-25 15:29:25 +02:00
Miroslav Stampar
3865b3a398
Minor improvement in case of technique E (when waiting for large entry - lots of chunks)
2016-05-25 12:50:53 +02:00
Miroslav Stampar
d6bcbbae1d
Minor patch for E technique to be more compatible with output of U technique
2016-05-25 12:42:15 +02:00
Miroslav Stampar
04b3aefc5d
Patch for special character output in U and E techniques
2016-05-25 12:24:36 +02:00
Miroslav Stampar
a5f8cae599
Fixes #1892
2016-05-24 17:58:35 +02:00
Miroslav Stampar
29c3037512
Better asciinema recording (shorter width)
2016-05-24 17:26:10 +02:00
Miroslav Stampar
d0d7d3a205
Update of location of a sample run
2016-05-24 17:12:44 +02:00
Miroslav Stampar
7ce36ea1b6
Removal of unused imports
2016-05-24 16:40:44 +02:00
Miroslav Stampar
6f97f4796b
Fixes #1891
2016-05-24 16:34:07 +02:00
Miroslav Stampar
39fe96009f
Minor improvement (related to the last commit)
2016-05-24 16:20:39 +02:00
Miroslav Stampar
b475a38895
Better ORDER BY detection
2016-05-24 15:46:06 +02:00
Miroslav Stampar
42de887b05
Language update
2016-05-24 15:18:19 +02:00
Miroslav Stampar
28576bf08e
Minor output update
2016-05-24 15:08:04 +02:00
Miroslav Stampar
c395958dff
Fixes #1888
2016-05-24 14:55:19 +02:00
Miroslav Stampar
798b539eec
Minor update
2016-05-24 14:50:56 +02:00
Miroslav Stampar
70cf8edc75
Fixes #1887
2016-05-24 14:17:00 +02:00
Miroslav Stampar
a81ea88eb0
Fixes #1889
2016-05-24 13:59:34 +02:00
Miroslav Stampar
023dda26fc
Minor update for --os-shell directories
2016-05-24 12:53:21 +02:00
Miroslav Stampar
3e76895155
Minor update
2016-05-24 12:30:01 +02:00
Miroslav Stampar
2c1bd7f034
Update for an Issue #1531 (MySQL quirk with international letters)
2016-05-24 12:01:02 +02:00
Miroslav Stampar
f7cae68378
More formal language
2016-05-22 21:44:17 +02:00
Miroslav Stampar
f6ff1a115a
Better (automatic) picking of a --string candidate (especially in case of international pages)
2016-05-22 21:29:08 +02:00
Miroslav Stampar
32ee586e2a
Minor language update
2016-05-22 14:30:32 +02:00
Miroslav Stampar
b9e5655e3c
Proper naming
2016-05-22 14:26:36 +02:00
Miroslav Stampar
6623c3f877
Pesky bug fix (nobody noticed :)
2016-05-22 14:22:31 +02:00
Miroslav Stampar
30a4173249
I like users which don't know the difference between detection and identification
2016-05-22 12:40:23 +02:00
Miroslav Stampar
dbbe4c6ddd
Fixes #1884
2016-05-22 11:44:21 +02:00
Miroslav Stampar
633e4dfe48
Fixes #1886
2016-05-22 11:37:27 +02:00
Miroslav Stampar
5e8b105677
Fixes #1880
2016-05-19 19:46:12 +02:00
Miroslav Stampar
414dd96bbd
Minor update (warning on negative integer values provided)
2016-05-19 18:04:25 +02:00
Miroslav Stampar
e857c2a88a
Update for an Issue #1879
2016-05-19 13:50:31 +02:00
Miroslav Stampar
e7aaea2b8e
Update for an Issue #1826
2016-05-17 14:10:49 +02:00
Miroslav Stampar
63d7cd607e
Minor patch (for late threading issues)
2016-05-17 13:54:42 +02:00
Miroslav Stampar
d886b08dd9
Update for an Issue #1826
2016-05-17 13:45:03 +02:00
Miroslav Stampar
72f3185ae7
Fixes #1878
2016-05-17 10:47:17 +02:00
Miroslav Stampar
03be9f9b65
Minor removal of blank lines
2016-05-17 10:43:16 +02:00
Miroslav Stampar
d9d0865c13
Another patch for an Issue #1874
2016-05-16 17:09:05 +02:00
Miroslav Stampar
e3f54bc226
Minor patch for #1874
2016-05-16 16:53:28 +02:00
Miroslav Stampar
9662f4a56a
Minor update
2016-05-16 16:47:29 +02:00
Miroslav Stampar
fea5cc8579
Minor patch
2016-05-16 15:37:49 +02:00
Miroslav Stampar
94091cd0e9
Fixes #1871
2016-05-15 09:37:45 +02:00
Miroslav Stampar
cc9f4b6102
Minor refactoring for MariaDB
2016-05-14 15:05:50 +02:00
Miroslav Stampar
cd7c99c752
Minor revert (it was not necessary - caused other problems)
2016-05-14 14:48:17 +02:00
Miroslav Stampar
75478c1181
Fixes #1868
2016-05-14 14:18:34 +02:00
Miroslav Stampar
ad0ca69579
Fixes #1865
2016-05-13 15:14:56 +02:00
Miroslav Stampar
2d801b7122
Minor patch for an Issue #1861
2016-05-12 17:16:55 +02:00
Miroslav Stampar
1e07269fe3
Patch for an Issue #1860
2016-05-12 16:42:12 +02:00
Miroslav Stampar
3b74e99576
Minor update (support for MariaDB)
2016-05-11 15:47:35 +02:00
Miroslav Stampar
439fff684e
Minor update (MSSQL CONCAT payload)
2016-05-11 09:42:54 +02:00
Miroslav Stampar
72cf06119c
Patch for an Issue #1852
2016-05-10 09:55:03 +02:00
Miroslav Stampar
808068d70a
Minor update
2016-05-10 09:19:59 +02:00
Miroslav Stampar
f09072b2b6
Fixes #1853
2016-05-09 13:13:02 +02:00
Miroslav Stampar
be9381abc5
Implements #1845
2016-05-06 13:06:59 +02:00
Miroslav Stampar
5d09f7b85f
Fixes #1822
2016-05-06 10:32:16 +02:00
Miroslav Stampar
8bbfee7591
Cleaning a leftover from be26392057
2016-05-06 10:30:58 +02:00
Miroslav Stampar
be26392057
Update for an Issue #1846
2016-05-06 10:23:57 +02:00
Miroslav Stampar
263730f4ee
Fixes #1840
2016-05-04 13:23:59 +02:00
Miroslav Stampar
5d7e1782d9
Fixes #1839
2016-05-04 11:14:42 +02:00
Miroslav Stampar
e27f590c2c
Fixes #1838
2016-05-04 11:11:58 +02:00
Miroslav Stampar
7afe655561
Another minor update for #1836
2016-05-03 12:52:46 +02:00
Miroslav Stampar
3bf08290a4
Update for an Issue #1836
2016-05-03 12:37:10 +02:00
Miroslav Stampar
34c2172391
Fixes #1837
2016-05-03 11:38:47 +02:00
Miroslav Stampar
48044f7a46
Minor update of IDS_WAF_CHECK_PAYLOAD
2016-05-03 00:19:19 +02:00
Miroslav Stampar
04e666182f
Minor update of FORMAT_EXCEPTION_STRINGS
2016-05-02 23:44:43 +02:00
Miroslav Stampar
c797129956
Fixes #1833
2016-05-02 11:10:12 +02:00
Miroslav Stampar
6928dae956
Minor patch
2016-05-02 10:45:50 +02:00
Miroslav Stampar
6db3bcbb51
Minor update for UrlScan
2016-05-02 10:12:19 +02:00
Miroslav Stampar
d7f0b3566d
Automatic monthly tagging
2016-05-02 10:06:30 +02:00
Miroslav Stampar
0c67a90cc0
Minor bug fix
2016-05-02 10:06:30 +02:00
Miroslav Stampar
f06e498fb0
Implementation for an Issue #1826
2016-04-29 14:19:32 +02:00
Miroslav Stampar
ad612bf9e4
Patch for Windows banner display
2016-04-29 00:51:20 +02:00
Miroslav Stampar
9dd5cd8eb6
Removing CloudFlare check
2016-04-29 00:17:07 +02:00
Miroslav Stampar
5ed3cdc819
Minor update
2016-04-22 10:54:55 +02:00
Miroslav Stampar
e07c92bce5
Minor change on banner showing up
2016-04-19 13:45:49 +02:00
Miroslav Stampar
0c5965c7b8
Minor patches
2016-04-19 13:13:37 +02:00
Miroslav Stampar
aa21550712
Minor patch for integer casting heuristics (circumvent auto-casting by DBMS itself)
2016-04-15 13:47:19 +02:00
Miroslav Stampar
66061e8c5f
Fixes #1811
2016-04-15 12:04:54 +02:00
Miroslav Stampar
c4b74c2e01
Fixes #1810
2016-04-12 22:37:14 +02:00
Miroslav Stampar
55b23e78ee
Fixes #1809
2016-04-12 22:10:26 +02:00
Miroslav Stampar
a9526bda92
Minor patch
2016-04-11 22:38:44 +02:00
Miroslav Stampar
0901da3f83
Update for an Issue #1807
2016-04-11 09:43:50 +02:00
Miroslav Stampar
8004652f7b
Some more optimization
2016-04-08 15:30:25 +02:00
Miroslav Stampar
c9b410c97f
Minor update
2016-04-08 14:59:52 +02:00
Miroslav Stampar
814d710320
Minor speed up
2016-04-08 14:41:34 +02:00
Miroslav Stampar
38fcc5a35a
Update for pre-WHERE payloads
2016-04-08 13:19:42 +02:00
Miroslav Stampar
674d516f3e
Minor patch
2016-04-08 11:40:09 +02:00
Miroslav Stampar
8ceb4907a5
Another update for Issue #1800
2016-04-08 11:37:38 +02:00
Miroslav Stampar
ce3749622a
Minor revisit of payload boundaries (Issue #1800 )
2016-04-08 11:28:17 +02:00
Miroslav Stampar
bcfae99701
Adding new WAF script
2016-04-08 10:32:18 +02:00
Miroslav Stampar
44c1c2c6f0
Minor update (reported via email)
2016-04-06 11:43:53 +02:00
Miroslav Stampar
ac08db82b2
Including one more error regex (based on testasp[.]vulnweb[.]com)
2016-04-04 16:14:30 +02:00
Miroslav Stampar
305bfd9d30
Implements #1763
2016-04-04 13:50:10 +02:00
Miroslav Stampar
f9aaec7b4a
Minor patch (binary extensions)
2016-04-04 12:43:53 +02:00
Miroslav Stampar
d881a92ee7
Automatic monthly tagging
2016-04-04 12:38:37 +02:00
Miroslav Stampar
60ada89347
Trying once again
2016-04-04 12:38:37 +02:00
Miroslav Stampar
171bfa33a7
Automatic monthly tagging
2016-04-04 12:34:19 +02:00
Miroslav Stampar
acaef90c7b
Minor tuning of auto tagging
2016-04-04 12:34:19 +02:00
Miroslav Stampar
31d7021d4c
Fixes #1794
2016-04-04 12:25:07 +02:00
Miroslav Stampar
e83d8f6143
Updating colorama (Issue #1784 )
2016-03-30 15:11:34 +02:00
Miroslav Stampar
0245ce6228
Fixes #1782
2016-03-28 19:55:33 +02:00
Miroslav Stampar
7e55af2811
Fixes #1778
2016-03-28 16:13:36 +02:00
Miroslav Stampar
ad3b766b65
Adding in-table name boundaries
2016-03-26 09:39:28 +01:00
Miroslav Stampar
074fbbcea5
Implementation for an Issue #1776
2016-03-23 15:45:49 +01:00
Miroslav Stampar
5b0d5970cc
Another patch related to the #1773
2016-03-23 10:33:32 +01:00
Miroslav Stampar
6c2f9859be
Potential patch for #1773
2016-03-23 10:26:22 +01:00
Miroslav Stampar
d496d99943
Fixes #1774
2016-03-22 13:24:54 +01:00
Miroslav Stampar
d20e9febf2
Fixes #1770
2016-03-19 17:40:05 +01:00
Miroslav Stampar
d76ee8f534
Further update for #1765
2016-03-17 17:06:11 +01:00
Miroslav Stampar
5b88e3e1ad
Minor update of version comment
2016-03-17 16:38:39 +01:00
Miroslav Stampar
a68848faf7
(Auto) adjusting micro version (to current month)
2016-03-17 16:31:34 +01:00
Miroslav Stampar
a4f21399e7
Fixes #1760
2016-03-17 16:23:28 +01:00
Miroslav Stampar
e03b2df58f
Fixes #1761
2016-03-14 17:21:35 +01:00
Miroslav Stampar
252eb97198
Patch related to the #1755
2016-03-12 19:28:28 +01:00
Miroslav Stampar
67ae620182
Another patch related to the #1752
2016-03-12 15:04:19 +01:00
Miroslav Stampar
13366aeb48
Fixes #1752
2016-03-12 12:26:30 +01:00
Miroslav Stampar
e1ce16144a
Fixes #1753
2016-03-10 15:42:01 +01:00
Miroslav Stampar
3307918389
Fixes #1750
2016-03-10 14:48:05 +01:00
Miroslav Stampar
c50849707f
Fixes #1748
2016-03-08 14:35:16 +01:00
Miroslav Stampar
06296bd251
Fixes #1743
2016-03-06 20:04:45 +01:00
Miroslav Stampar
0f6e529fb9
Fixes #1745
2016-03-06 12:14:20 +01:00
Miroslav Stampar
242800c085
Minor update related to the #1740
2016-03-01 15:40:34 +01:00
Miroslav Stampar
da5fff7775
Merge pull request #1740 from crashbrz/patch-1
...
Update errors.xml
2016-03-01 15:37:34 +01:00
Miroslav Stampar
679f0cf772
Fixes #1738
2016-03-01 15:36:00 +01:00
Ewerson Guimaraes (Crash)
8df56ecc72
Update errors.xml
...
Add support to Sybase 15.7 error based
2016-03-01 15:13:38 +01:00
Miroslav Stampar
1b5a4651a9
Trivial refactoring
2016-03-01 14:48:53 +01:00
Miroslav Stampar
05fa7eb7c6
Minor update
2016-03-01 11:56:56 +01:00
Miroslav Stampar
336169e181
Update of version display
2016-02-29 08:12:38 +01:00
Miroslav Stampar
b2bc3d49fd
Minor update
2016-02-29 00:52:46 +01:00
Miroslav Stampar
71aa7deefe
Minor beautification
2016-02-29 00:49:45 +01:00
Miroslav Stampar
cf5ae507c8
Minor update of READMEs
2016-02-29 00:44:08 +01:00
Miroslav Stampar
4898a2c332
Dummy commit
2016-02-29 00:30:37 +01:00
Miroslav Stampar
151dcee32e
Minor update
2016-02-29 00:23:59 +01:00
Miroslav Stampar
73f1155847
Adding new shutils file
2016-02-29 00:20:58 +01:00
Miroslav Stampar
fcf9998010
Adding support for Travis CI
2016-02-29 00:04:31 +01:00
Miroslav Stampar
26b895dd2e
Merge pull request #1733 from Aikes/master
...
Fixes file path traversal issue on win platform.
2016-02-28 23:35:09 +01:00
Miroslav Stampar
c66607c998
Merge pull request #1735 from sqlmapproject/1.0
...
Adjusting version number
2016-02-27 16:02:55 +01:00
Miroslav Stampar
adfcb1ad67
Adjusting version number
2016-02-27 15:59:52 +01:00
Miroslav Stampar
f190327da3
Minor update
2016-02-27 15:41:15 +01:00
Miroslav Stampar
76b1aca0c7
Update of DOCs
2016-02-27 15:28:31 +01:00
Miroslav Stampar
db51af6ee1
Minor update
2016-02-27 15:26:51 +01:00
Aikes
b4bb4c393b
Fixes file path traversal issue on win platform.
...
POC: GET /download/b31146dcdb92e5db/C:\windows\win.ini/a
2016-02-27 00:10:32 +08:00
Miroslav Stampar
d69ef5ec49
Merge pull request #1732 from enisozgen/master
...
Turkish translation
2016-02-25 21:44:39 +01:00
Enis Ozgen
a3c9e441a7
Turkish translation
2016-02-25 15:19:54 +02:00
Miroslav Stampar
21885021e7
Fixes #1731
2016-02-25 13:34:41 +01:00
Miroslav Stampar
98972d0740
Moving CONTRIBUTING.md to doc directory
2016-02-25 09:41:21 +01:00
Miroslav Stampar
c5ecdb5403
Minor update related to the Issue #1730
2016-02-25 01:20:48 +01:00
Miroslav Stampar
1e4b824827
Minor update
2016-02-23 23:58:53 +01:00
Miroslav Stampar
b11242ec15
Update of CHANGELOG.md
2016-02-23 22:51:08 +01:00
Miroslav Stampar
a90913c57d
Proper patch for #1723
2016-02-23 11:46:04 +01:00
Miroslav Stampar
256b1988b9
Fixes #1726
2016-02-23 11:06:52 +01:00
Miroslav Stampar
c99e974be2
Merge pull request #1728 from LionNatsu/patch-2
...
Minor change: typo
2016-02-23 11:02:10 +01:00
Lion Yang
bc6cc4bc1d
Remove a whitespace tail
2016-02-23 16:57:06 +08:00
Miroslav Stampar
3a94435cce
Minor update
2016-02-18 13:56:47 +01:00
Miroslav Stampar
d6bac363af
Minor patch for combo -r and --method
2016-02-18 11:13:51 +01:00
Miroslav Stampar
82abf1f742
Fixes #1714
2016-02-16 09:56:53 +01:00
Miroslav Stampar
4cd3813f68
Patch to include traceback into the sqlmapapi based unhandled exception messages
2016-02-16 09:15:57 +01:00
Miroslav Stampar
cc06871075
Adding some debug messages for future-self
2016-02-16 08:58:18 +01:00
Miroslav Stampar
08d733cf02
Fixes #1709
2016-02-15 00:00:48 +01:00
Miroslav Stampar
4ee0495352
Merge pull request #1710 from Noelkd/remove-dead-links
...
Removed dead links.
2016-02-14 22:56:25 +01:00
Noelkd
0514946efa
Removed dead links.
2016-02-14 15:57:55 +00:00
Miroslav Stampar
4237333dca
Minor nuisance patch
2016-02-13 21:28:02 +01:00
Miroslav Stampar
78e503d7b2
Minor patch related to the #1706
2016-02-13 21:25:01 +01:00
Miroslav Stampar
9d18d48a6e
Minor consistency patch
2016-02-13 21:18:56 +01:00
Miroslav Stampar
410df455ab
Minor consistency patch
2016-02-13 21:03:05 +01:00
Miroslav Stampar
d7cdb6cbd8
Minor update
2016-02-06 20:16:33 +01:00
Miroslav Stampar
cedfdc78f4
Adding escapequotes.py (utility tamper script)
2016-02-05 12:00:57 +01:00
Miroslav Stampar
08aae2b7c5
Bug fix (--prefix should not fix the origValue in REPLACEMENT payloads)
2016-02-05 11:53:24 +01:00
Miroslav Stampar
b07685a386
Added checking of localhost for another DNS service on *:53
2016-02-03 11:55:13 +01:00
Miroslav Stampar
4916f1b2b2
Minor path related to the #1676
2016-01-28 09:10:04 +01:00
Miroslav Stampar
954b4ec32b
Fix for #1676
2016-01-27 21:25:34 +01:00
Miroslav Stampar
ee0439cf11
Update for #1678
2016-01-27 10:03:30 +01:00
Miroslav Stampar
3605b98e84
Merge pull request #1678 from dozysun/servername-option
...
add --adapter option to support various of bottle server adapter
2016-01-27 09:44:31 +01:00
dozysun
997362f61b
change option name to adapter
2016-01-27 10:35:18 +08:00
Miroslav Stampar
62f94f6587
Adding comments (Issue #1681 )
2016-01-26 07:52:25 +01:00
Miroslav Stampar
f532ad3c9c
Minor bug fix
2016-01-26 07:32:47 +01:00
Miroslav Stampar
c34eaa1ce8
Minor patch
2016-01-24 22:05:08 +01:00
dozysun
f5ffd9fa02
add --servername option to support various of bottle server adapter
2016-01-22 11:33:12 +08:00
Miroslav Stampar
c6c5a937f9
Minor style update
2016-01-21 10:17:17 +01:00
Miroslav Stampar
574b3a79aa
Adding support for detection of CloudFlare responses
2016-01-21 10:16:23 +01:00
Miroslav Stampar
034de9676e
Closes #1675
2016-01-20 09:33:05 +01:00
Miroslav Stampar
f54b25ca2a
Adding one more regex for MsAccess error recognition
2016-01-17 15:22:53 +01:00
Miroslav Stampar
8d42a93fdc
Fixes #1665
2016-01-16 08:13:56 +01:00
Miroslav Stampar
6fef2948ff
Minor consistency update
2016-01-14 22:51:26 +01:00
Miroslav Stampar
66eaac862b
Minor consistency update
2016-01-14 22:47:56 +01:00
Miroslav Stampar
59695af101
Minor improvement of heuristic checks
2016-01-14 22:21:47 +01:00
Miroslav Stampar
8b90d146f6
Update of file attributes
2016-01-14 18:02:15 +01:00
Miroslav Stampar
df8e4b504d
Patch for special cases of OR boolean-based blind (covered with last two commits)
2016-01-14 13:51:30 +01:00
Miroslav Stampar
bdcf3fffba
Minor update related to the last (error results in OR boolean-based blind should not be the same as True to be able to do proper comparison)
2016-01-14 13:40:50 +01:00
Miroslav Stampar
c7ef9429ae
Minor check for problematic injections
2016-01-14 13:16:44 +01:00
Miroslav Stampar
c78a9cd156
Consistency patch
2016-01-14 12:14:00 +01:00
Miroslav Stampar
4c1fc095d8
Adding heuristic check for FI vulnerability
2016-01-14 09:59:13 +01:00
Miroslav Stampar
a8c6c6fca1
Minor update related to the last one
2016-01-13 23:47:34 +01:00
Miroslav Stampar
4e29e1b351
Fixing wrong commit #4f939b5719716dfe9bd085c4f67696bc11064edd
2016-01-13 23:34:42 +01:00
Miroslav Stampar
8362bdcf66
Fix for screw up made by #52dd92748a50bcee4fb979ea49185840ff6743b9
2016-01-13 23:16:27 +01:00
Miroslav Stampar
87676eb4bb
Minor update for #1660
2016-01-13 23:05:28 +01:00
Miroslav Stampar
c410f16f3f
Fixes #1660
2016-01-13 23:02:11 +01:00
Miroslav Stampar
e9745cc0be
Minor just in case patch
2016-01-13 22:47:42 +01:00
Miroslav Stampar
0c8c4fa0d9
Fixes #1663
2016-01-13 14:38:59 +01:00
Miroslav Stampar
c37f4855bb
Another patch for Issue #1659
2016-01-12 10:34:56 +01:00
Miroslav Stampar
eb989469f3
Minor just in case update
2016-01-12 10:27:04 +01:00
Miroslav Stampar
9b716fcce9
Patch related to the #1659
2016-01-12 10:24:28 +01:00
Miroslav Stampar
a0b67418c7
Just in case update
2016-01-11 00:34:03 +01:00
Miroslav Stampar
7e78554e97
For frenzy Ctrl-C pressing
2016-01-11 00:08:38 +01:00
Miroslav Stampar
78a512500d
Better place for setting flags
2016-01-11 00:03:22 +01:00
Miroslav Stampar
1f01d6022c
Minor style update
2016-01-10 23:50:24 +01:00
Miroslav Stampar
ab3ff0257a
Minor patch
2016-01-10 23:27:32 +01:00
Miroslav Stampar
2280cd191a
Fixes #1654
2016-01-10 23:15:43 +01:00
Miroslav Stampar
e53e4dddf1
Minor patch
2016-01-10 23:12:46 +01:00
Miroslav Stampar
e519ed2e18
Another patch related to the #1655
2016-01-10 23:07:11 +01:00
Miroslav Stampar
8b01996adf
Patch related to the #1655
2016-01-10 22:59:40 +01:00
Miroslav Stampar
6b40e0aa8c
Minor style update (nongit-version)
2016-01-10 02:08:23 +01:00
Miroslav Stampar
85b35f44a0
Minor refactoring for #1637
2016-01-09 17:39:53 +01:00
Miroslav Stampar
0017c17e7d
Merge pull request #1637 from jakxx/master
...
Addition to IBM DB2 SQL Error Identification
2016-01-09 17:39:06 +01:00
Miroslav Stampar
5908964db4
Another (better) patch for #1636
2016-01-09 17:32:19 +01:00
Miroslav Stampar
0f8a551227
Potential patch for #1636
2016-01-09 00:55:01 +01:00
Miroslav Stampar
3c9be947c5
Fixes #1649
2016-01-09 00:15:05 +01:00
Miroslav Stampar
48ac2101f2
Using only once the dummy checkWaf payload
2016-01-08 23:23:41 +01:00
Miroslav Stampar
de06ae6803
Fixes #1647
2016-01-08 23:10:32 +01:00
Miroslav Stampar
c7ea3d65be
Fixes #1644
2016-01-08 15:33:14 +01:00
Miroslav Stampar
e3650342bd
Fixes #1639
2016-01-08 11:47:12 +01:00
Miroslav Stampar
b427f6c03e
Minor bug fix
2016-01-08 10:52:02 +01:00
Miroslav Stampar
6f3511dcc3
Error chunk length bug fix (reported privately)
2016-01-08 10:45:31 +01:00
Miroslav Stampar
b43c1747e0
Minor refactoring
2016-01-07 21:58:10 +01:00
Miroslav Stampar
c5d3198101
Minor refactoring
2016-01-07 21:46:20 +01:00
Andrew Smith
777e4a3db2
Update for false positives
...
Attempt to eliminate false positives using more specific regex
2016-01-07 15:42:22 -05:00
Andrew Smith
b84d787f4a
Addition of IBM DB2 Error Codes
2016-01-07 10:15:09 -05:00
Miroslav Stampar
9b70728441
Minor update
2016-01-06 00:12:24 +01:00
Miroslav Stampar
d565740b8a
Update of copyright string
2016-01-06 00:07:49 +01:00
Miroslav Stampar
d0d676ccce
Update of copyright string
2016-01-06 00:06:12 +01:00
Miroslav Stampar
59ff8114ff
Fixes #1635
2016-01-04 12:09:08 +01:00
Miroslav Stampar
7d334cca48
Minor style patch
2016-01-04 12:08:56 +01:00
Miroslav Stampar
03160d99eb
Fixes #1630
2015-12-30 13:39:08 +01:00
Miroslav Stampar
42066cfb3d
Minor refactoring
2015-12-30 12:41:56 +01:00
Miroslav Stampar
dd8fcaeb43
Minor refactoring of some revisited code
2015-12-29 14:32:13 +01:00
Miroslav Stampar
fc5802f461
Fixes #1628
2015-12-29 13:19:25 +01:00
Miroslav Stampar
849babaf8d
Minor patch for too fast Ctrl-C(-ers)
2015-12-28 11:39:46 +01:00
Miroslav Stampar
24d95ab6b3
Fixes #1624
2015-12-24 10:34:42 +01:00
Miroslav Stampar
3454e356f9
Fixes #1621
2015-12-23 08:55:45 +01:00
Miroslav Stampar
7411ff93e5
Minor update related to the #1620
2015-12-23 08:14:18 +01:00
Miroslav Stampar
ae7481081e
Patch for an Issue reported via email
2015-12-19 23:45:10 +01:00
Miroslav Stampar
89e0fc8ffa
Minor update
2015-12-19 17:50:12 +01:00
Miroslav Stampar
1f6caba725
Merge pull request #1614 from getcode2git/master
...
update some feature
2015-12-19 17:46:43 +01:00
getcode2git
eb79b0aae8
Create safe3.py
...
Safe3 Web Application Firewall
2015-12-19 15:41:25 +08:00
getcode2git
7ed7497fda
update safedog.py
...
update some feature
2015-12-19 15:39:14 +08:00
Miroslav Stampar
e4ed1c058b
Minor error message improvement (SSL issues)
2015-12-18 17:15:59 +01:00
Miroslav Stampar
aee47d32c5
Patch for #1601
2015-12-15 12:13:03 +01:00
Miroslav Stampar
d7d786d3b5
Fixes #1607
2015-12-15 11:29:37 +01:00
Miroslav Stampar
b269e8418f
Fixes #1608
2015-12-15 10:46:37 +01:00
Miroslav Stampar
dc7f2a71d2
Minor refactoring
2015-12-12 23:48:30 +01:00
Miroslav Stampar
273679f542
Adding new charset replacement (reported via email)
2015-12-10 13:23:50 +01:00
Miroslav Stampar
663c976a3b
Fixes #1600
2015-12-09 19:53:48 +01:00
Miroslav Stampar
2eb5f5e841
Handling 'address already in use' for sqlmapapi server instance
2015-12-09 12:20:09 +01:00
Miroslav Stampar
31d250f98e
Fixes #1592
2015-12-09 12:00:34 +01:00
Miroslav Stampar
1c5c937507
Minor update
2015-12-09 10:14:13 +01:00
Miroslav Stampar
efc91b015d
Fixes #1589
2015-12-09 10:07:37 +01:00
Miroslav Stampar
af60f11319
Fixes #1584 (hello @w3af looking for the patch of this one ;)
2015-12-07 16:17:28 +01:00
Miroslav Stampar
b5b3411f16
Fixes #1574
2015-12-06 23:49:22 +01:00
Miroslav Stampar
d5e6be41db
Fixes #1582
2015-12-06 23:24:09 +01:00
Miroslav Stampar
7517e64417
Minor bug fix (reported via email)
2015-12-05 00:52:58 +01:00
Miroslav Stampar
d50c0b7103
Fixes #1581
2015-12-03 12:16:00 +01:00
Miroslav Stampar
c6d4217495
Minor update (just in case)
2015-12-03 02:08:59 +01:00
Miroslav Stampar
a7c135174c
Fixes #1579
2015-12-03 02:00:16 +01:00
Miroslav Stampar
6397704456
Patch for an Issue #1578
2015-12-03 01:43:37 +01:00
Miroslav Stampar
80d3ff6706
Adding hidden switch for disabling socket preconnect (debugging purposes)
2015-12-02 12:05:40 +01:00
Miroslav Stampar
a219ff9a92
Fixes #1572
2015-11-29 19:40:14 +01:00
Miroslav Stampar
795777b7c5
Minor patch
2015-11-28 22:44:42 +01:00
Miroslav Stampar
5f2c31f8ec
Minor consistency patch
2015-11-28 22:42:25 +01:00
Miroslav Stampar
f9da29284c
Minor bug fix (reported via email)
2015-11-27 18:35:58 +01:00
Miroslav Stampar
c7ec1534a6
Patch related to #1256
2015-11-25 13:04:34 +01:00
Miroslav Stampar
a18c69d78b
Fixes #1564
2015-11-25 10:21:32 +01:00
Miroslav Stampar
829351421f
Minor cosmetics
2015-11-25 10:12:07 +01:00
Miroslav Stampar
5020269f50
Adding extra mark into non-git checkouts
2015-11-24 09:38:28 +01:00
Miroslav Stampar
527dcce08d
Better alternative (on Linux getctime() is the time of the last metadata change)
2015-11-24 09:25:11 +01:00
Miroslav Stampar
436d87dee1
Fixes #1560
2015-11-24 09:18:46 +01:00
Miroslav Stampar
6c083956f4
Patch related to the #1557
2015-11-23 09:48:43 +01:00
Miroslav Stampar
bdb496eaa5
Fixes #1558
2015-11-23 09:24:30 +01:00
Miroslav Stampar
b2dc443835
Fixes #1559
2015-11-23 09:20:35 +01:00
Miroslav Stampar
4d576928a7
Fixes #1554
2015-11-22 16:05:48 +01:00
Miroslav Stampar
376037123b
Minor fix
2015-11-22 15:33:00 +01:00
Miroslav Stampar
763b72a3ed
Fixes #1551
2015-11-20 17:01:41 +01:00
Miroslav Stampar
a5489516eb
Fixes #1550
2015-11-20 16:52:59 +01:00
Miroslav Stampar
7fa9c8e938
Patch for an Issue #1546
2015-11-20 11:38:26 +01:00
Miroslav Stampar
efe41fbdc7
Fixes #1547
2015-11-20 11:32:54 +01:00
Miroslav Stampar
69bc875eb3
Minor consistency update (with other WAF scripts) for #1543
2015-11-18 09:04:01 +01:00
Miroslav Stampar
378005d438
Merge pull request #1543 from Wyc0/master
...
enhance recognition of "baiduyun" in waf/baidu.py
2015-11-18 09:01:27 +01:00
Wyc0
2ff4b78dbb
enhance recognition of "baiduyun" in waf/baidu.py
2015-11-18 12:31:40 +08:00
Miroslav Stampar
39a7b78737
Minor fix
2015-11-17 09:39:09 +01:00
Miroslav Stampar
19f6eb234b
Revert of #58e049a60d250b881af60091215c75daa3f5c01a (I can imagine couple of things that could go wrong)
2015-11-17 08:52:24 +01:00
Miroslav Stampar
58e049a60d
More generic approach for number of pre-open sockets (Issue #1540 )
2015-11-17 02:45:27 +01:00
Miroslav Stampar
fd2908336a
Minor just in case patch
2015-11-17 02:35:53 +01:00
Miroslav Stampar
5be0a83e94
Minor patch
2015-11-17 01:38:43 +01:00
Miroslav Stampar
89abeb0244
Patch for 'Exception in thread Thread-1 (most likely raised during interpreter shutdown)'
2015-11-17 01:09:57 +01:00
Miroslav Stampar
abb1c6a621
Less intensive loop
2015-11-17 00:12:04 +01:00
Miroslav Stampar
41b8dfab86
Implementation for an Issue #1540
2015-11-16 23:46:10 +01:00
Miroslav Stampar
4335ae8330
Patching previous commit
2015-11-16 16:59:54 +01:00
Miroslav Stampar
94639d11a3
Another update related to the #1539
2015-11-16 15:33:05 +01:00
Miroslav Stampar
c1e3431877
Minor patch
2015-11-16 15:32:28 +01:00
Miroslav Stampar
768e5da589
Removing leftover (from 5593bf2fee)
2015-11-16 15:04:09 +01:00
Miroslav Stampar
5593bf2fee
Another patch related to #1539 (simplifying unicode bad chars and preventing double encoding of safe chars)
2015-11-16 15:02:30 +01:00
Miroslav Stampar
ca933fcf1d
Another patch for #1539
2015-11-16 14:08:43 +01:00
Miroslav Stampar
a212f0c240
Another patch for #1539
2015-11-16 12:56:15 +01:00
Miroslav Stampar
9c69f56a34
Proper patch for an Issue #1539
2015-11-16 11:59:09 +01:00
Miroslav Stampar
fb2cb25afe
Bug fix for an Issue #1539
2015-11-16 11:56:15 +01:00
Miroslav Stampar
a6ea19067b
Merge pull request #1535 from loveshell/patch-1
...
add Newdefend waf identified
2015-11-15 16:31:40 +01:00
loveshell
ee7ea68c15
add Newdefend waf identified
2015-11-15 10:15:05 +08:00
Miroslav Stampar
8d1e1ea474
Patch for an Issue #1532
2015-11-12 16:58:34 +01:00
Miroslav Stampar
d772e7e1d5
Fixes #1529
2015-11-11 16:07:11 +01:00
Miroslav Stampar
07b1407345
Patches #1530
2015-11-11 15:55:28 +01:00
Miroslav Stampar
bc215d1b19
I believe that this was a wrong decision. Patching
2015-11-09 14:11:08 +01:00
Miroslav Stampar
17350fb4ec
Proper fix for #1146 (/ has been escaped with \/ in output)
2015-11-09 14:05:53 +01:00
Miroslav Stampar
22484c8599
Bug fix (-p Host didn't work, while -p host worked)
2015-11-09 13:19:55 +01:00
Miroslav Stampar
42649005c2
Lots of fixes and refactoring in search department
2015-11-08 16:37:46 +01:00
Miroslav Stampar
b4526a3d51
Bug fix (usage of socks and http proxies in --proxy-file didn't work together)
2015-11-08 02:20:29 +01:00
Miroslav Stampar
9849f87b61
Minor just in case patch
2015-11-08 00:10:28 +01:00
Miroslav Stampar
193f8190c4
Adding new warning message
2015-11-07 23:30:24 +01:00
Miroslav Stampar
b86b7c06e9
Author forgot to update the version
2015-11-07 22:47:55 +01:00
Miroslav Stampar
08054dec7b
Newer version of pydes
2015-11-07 22:41:56 +01:00
Miroslav Stampar
78e3e52ab0
Newer version of bs3
2015-11-07 22:39:20 +01:00
Miroslav Stampar
427abbc0e3
New version of bottle
2015-11-07 22:34:13 +01:00
Miroslav Stampar
c31e23e514
Patch for an Issue #1516
2015-11-06 11:19:55 +01:00
Miroslav Stampar
5198e4c816
Minor bug fix (based on private user report)
2015-11-04 15:04:38 +01:00
Miroslav Stampar
3451372d4e
Fixes #1521
2015-11-04 14:48:40 +01:00
Miroslav Stampar
6adb6eabec
Fixes #1517
2015-11-03 14:53:41 +01:00
Miroslav Stampar
064c2a71ed
Fixes #1510
2015-11-01 22:56:26 +01:00
Miroslav Stampar
bae9db65ab
Minor update
2015-10-31 16:33:48 +01:00
Miroslav Stampar
2642e453b5
New tamper script
2015-10-31 16:24:32 +01:00
Miroslav Stampar
537f39edd8
Minor patches for spanish translation (thanks to @lightos)
2015-10-31 10:55:07 +01:00
Miroslav Stampar
f0150f8c8c
Merge pull request #1500 from tonyskapunk/es-MX
...
Adding translation for README in Spanish(MX).
2015-10-31 10:50:34 +01:00
Miroslav Stampar
4dc0c05172
Fixes #1505
2015-10-31 10:16:44 +01:00
tonyskapunk
d0ea5677de
Adding translation for README in Spanish(MX).
2015-10-29 20:30:30 +00:00
Miroslav Stampar
04aaa5985b
Fixes #1497
2015-10-29 17:02:47 +01:00
Miroslav Stampar
0b64cf803c
Fixes #1496
2015-10-29 16:52:17 +01:00
Miroslav Stampar
d41cd53d31
Minor style fix (distinguish form from URL testing when --forms --crawl combo used)
2015-10-28 14:03:21 +01:00
Miroslav Stampar
caafa377a6
Fixes #1495
2015-10-28 10:29:12 +01:00
Miroslav Stampar
8fbac5a99e
Patch for --proxy-file
2015-10-25 15:58:43 +01:00
Miroslav Stampar
89e36392f7
Fixes #1486
2015-10-25 15:32:02 +01:00
Miroslav Stampar
1b81084106
Fixes #1484
2015-10-23 23:48:41 +02:00
Miroslav Stampar
2c754b57bb
Minor patch
2015-10-23 14:29:48 +02:00
Miroslav Stampar
8f9979c302
Patch for an Issue #541
2015-10-22 20:51:05 +02:00
Miroslav Stampar
5fb8ae9d3c
Fixes #1479
2015-10-22 19:59:16 +02:00
Miroslav Stampar
fbec463b49
Adding new bold patterns
2015-10-22 15:44:08 +02:00
Miroslav Stampar
7c1cff6749
Fixing ancient bug (introduced with #6c80f29) - that removes original value when --prefix used
2015-10-22 15:14:12 +02:00
Miroslav Stampar
90ad914c1e
Patch related to the #1477
2015-10-22 14:58:06 +02:00
Miroslav Stampar
5ff59296ef
Space after the generic comments has to be "protected"
2015-10-22 14:47:19 +02:00
Miroslav Stampar
8aada250f3
Fixes #1471
2015-10-19 11:08:58 +02:00
Miroslav Stampar
3dc8820caa
Fixes #1474
2015-10-19 10:38:38 +02:00
Miroslav Stampar
441196f360
Fixes #1470
2015-10-16 23:59:39 +02:00
Miroslav Stampar
d762098cce
Leaving a reference just in case
2015-10-15 16:51:53 +02:00
Miroslav Stampar
c51de99a25
Minor revert
2015-10-15 16:38:48 +02:00
Miroslav Stampar
20559fd52c
Minor patch
2015-10-15 16:01:09 +02:00
Miroslav Stampar
f793a26095
Removing ugly duplicating of \ (hidden bugs came - e.g. DNS exfiltration)
2015-10-15 16:00:59 +02:00
Miroslav Stampar
956047b43f
Patch for an Issue #1468
2015-10-15 13:07:43 +02:00
Miroslav Stampar
475ca5277a
Minor information update regarding #541
2015-10-14 16:11:11 +02:00
Miroslav Stampar
e3ae026077
Fixes #1467
2015-10-14 15:19:44 +02:00
Miroslav Stampar
80aca35dd1
Removing #1450
2015-10-13 15:00:59 +02:00
Miroslav Stampar
c4df6f3a22
Fixes #1465
2015-10-13 13:31:28 +02:00
Miroslav Stampar
570562369b
Further fixes for sqlmap to work properly with HSQLDB (WebGoat)
2015-10-13 13:04:59 +02:00
Miroslav Stampar
48619d9ae1
Fixes #1464
2015-10-12 10:05:49 +02:00
Miroslav Stampar
b9a44555ff
Fixes #1462
2015-10-11 15:20:10 +02:00
Miroslav Stampar
47a42c234e
Fixes #1459
2015-10-10 19:19:50 +02:00
Miroslav Stampar
ecef769200
More generic approach (non-: versions appear too)
2015-10-10 15:23:09 +02:00
Miroslav Stampar
786b51e6e4
Minor patch
2015-10-10 15:18:47 +02:00
Miroslav Stampar
17ee402592
Adding error regexes for HSQLDB
2015-10-10 14:53:08 +02:00
Miroslav Stampar
51444276c0
Better dealing with MySQL vs HSQLDB
2015-10-10 14:19:47 +02:00
Miroslav Stampar
9641e84dd9
Bug fixes for HSQLDB
2015-10-09 16:52:13 +02:00
Miroslav Stampar
fa4e867035
Bug fix for MySQL fingerprinting (excluding HSQLDB MySQL look-alike)
2015-10-09 14:17:13 +02:00
Miroslav Stampar
41db0e0eea
range to xrange (leftovers)
2015-10-09 13:48:21 +02:00
Miroslav Stampar
439d003753
Adding new version of chardet
2015-10-09 13:35:48 +02:00
Miroslav Stampar
d424d4cdc7
Fixes #1457
2015-10-09 11:54:28 +02:00
Miroslav Stampar
8bf236ce11
Minor patch for SQLite parsing of schemas
2015-10-07 10:01:48 +02:00
Miroslav Stampar
fd686fb691
Patch related to the #1455
2015-10-07 09:43:25 +02:00
Miroslav Stampar
eb7c18d1f8
Fixes #1452
2015-10-07 09:25:14 +02:00
Miroslav Stampar
657d71119b
Fixes #1453
2015-10-07 09:22:11 +02:00
Miroslav Stampar
78bbf5d63c
Fixes #1451
2015-10-06 14:17:35 +02:00
Miroslav Stampar
551b7e4b45
Patch for an Issue #1450
2015-10-06 13:23:01 +02:00
Miroslav Stampar
95ce5a4a09
Fixes #1444
2015-10-05 16:33:10 +02:00
Miroslav Stampar
b98f84a610
Fixes #1443
2015-10-05 16:26:12 +02:00
Miroslav Stampar
1258b354c3
Minor refactoring
2015-10-05 16:09:58 +02:00
Miroslav Stampar
20c19f33dc
Minor update
2015-10-05 15:51:21 +02:00
Miroslav Stampar
1c6e288eb1
Fixes #1447
2015-10-05 15:33:29 +02:00
Miroslav Stampar
acd6b7797f
Fixes #1446
2015-10-05 15:18:54 +02:00
Miroslav Stampar
53de0e8949
Implements #1442
2015-10-01 11:57:33 +02:00
Miroslav Stampar
29edb4f75c
Fixes #1440
2015-09-30 11:26:56 +02:00
Miroslav Stampar
a1a7161fab
Fixes #1441
2015-09-30 10:13:19 +02:00
Miroslav Stampar
5ce4d4d2ec
Fixes #1439
2015-09-29 10:10:39 +02:00
Miroslav Stampar
906cb6d3c2
Removing a hard limit to use --start/--stop only for --dump scenarios
2015-09-28 11:11:39 +02:00
Miroslav Stampar
ac467bc453
Fixes #1437
2015-09-28 09:54:41 +02:00
Miroslav Stampar
1fd6b007ab
Less critical messages when something goes wrong with connection
2015-09-27 16:36:20 +02:00
Miroslav Stampar
ef22f31fdf
Fixes #1433
2015-09-27 16:17:58 +02:00
Miroslav Stampar
5bade7947b
Fixes #1435
2015-09-27 16:09:02 +02:00
Miroslav Stampar
5ed106ecea
Patch for an Issue #1434
2015-09-27 15:59:17 +02:00
Miroslav Stampar
38541b021a
Implementing hidden switch '--force-threads' on request (to force multi-threading in time-based SQLi)
2015-09-26 00:09:17 +02:00
Miroslav Stampar
b68891050d
Better word used
2015-09-25 23:41:47 +02:00
Miroslav Stampar
f16389232f
Bug fix for --proxy-file (only first element was fetched in case of fail)
2015-09-25 15:23:42 +02:00
Miroslav Stampar
4774795d8c
Fixes #1429
2015-09-25 14:59:21 +02:00
Miroslav Stampar
d28c72b6f1
Another fix for Python 2.6 (bug introduced with ff7be9d0eb)
2015-09-24 16:26:52 +02:00
Miroslav Stampar
ea4cef9c6d
Skipping quit exception in case of --search
2015-09-24 13:44:51 +02:00
Miroslav Stampar
e19b097ab5
Bug fix (--columns has been broken for last couple of days)
2015-09-24 11:49:05 +02:00
Miroslav Stampar
12b9939baa
Minor refactoring
2015-09-24 10:24:37 +02:00
Miroslav Stampar
29bdcf0e65
Fixes #1425
2015-09-23 15:31:25 +02:00
Miroslav Stampar
aa088aafd2
Looks more technical
2015-09-23 08:47:52 +02:00
Miroslav Stampar
158ae501c1
Bug fix for tamper script equaltolike (has been doing problems when used with MsSQL)
2015-09-22 14:32:52 +02:00
Miroslav Stampar
058f63a050
Patch for annoying retrieval of columns during dump (if -C used)
2015-09-22 12:33:11 +02:00
Miroslav Stampar
03da24b249
Minor cosmetics
2015-09-22 12:03:47 +02:00
Miroslav Stampar
74294ae105
Bug fix for --common-tables in case of MsSQL/Sybase (safeSQLIdentificatorNaming already used)
2015-09-22 11:28:56 +02:00
Miroslav Stampar
0e22a0ca5f
Minor cosmetics
2015-09-21 16:41:54 +02:00
Miroslav Stampar
81caf14b6d
Adding switch --skip-waf
2015-09-21 14:57:44 +02:00
Miroslav Stampar
e81e474646
Minor adjustment
2015-09-21 14:46:34 +02:00
Miroslav Stampar
56f0b811a6
Minor patch
2015-09-21 13:23:56 +02:00
Miroslav Stampar
3fca379f29
Minor patch (avoiding message 'can't establish SSL connection' in --check-tor)
2015-09-21 11:25:59 +02:00
Miroslav Stampar
f96edc951c
Patches #1419
2015-09-21 11:02:56 +02:00
Miroslav Stampar
27707be467
Fixes #1416
2015-09-17 17:09:36 +02:00
Miroslav Stampar
aa2112b360
Update for #1414
2015-09-17 16:18:58 +02:00
Miroslav Stampar
7cfa90830d
Merge pull request #1414 from daremon/api-client-2
...
Added commands stop, kill, list to API client
2015-09-17 15:51:12 +02:00
Miroslav Stampar
65a8f0fe32
Minor enhancement
2015-09-17 15:25:40 +02:00
Miroslav Stampar
2cea977e12
Fixes #1415
2015-09-17 14:58:01 +02:00
daremon
c2fb2161d3
Added flush command
2015-09-16 00:15:16 +03:00
daremon
ff7be9d0eb
Fixed list command
2015-09-16 00:01:57 +03:00
Miroslav Stampar
c59ead36ce
Patch for Python 2.6 (SyntaxError)
2015-09-15 17:23:59 +02:00
Miroslav Stampar
058870635b
Update for an #1414
2015-09-15 14:37:30 +02:00
Miroslav Stampar
ee38574449
Fixes #1411
2015-09-15 13:26:25 +02:00
Miroslav Stampar
5de1825d0c
Fixes #1412
2015-09-15 10:48:23 +02:00
daremon
1417decdf1
Added commands stop, kill, list to API client
2015-09-14 17:31:02 +03:00
Miroslav Stampar
5ce3306114
Adding new tamper script (Issue #1247 )
2015-09-13 14:47:27 +02:00
Miroslav Stampar
f89ce2173f
Fixes #1404
2015-09-12 15:13:30 +02:00
Miroslav Stampar
c4f9e66a6f
Patch related to the #1403
2015-09-10 16:21:31 +02:00
Miroslav Stampar
c05c0ff435
Minor patch with imports
2015-09-10 15:55:49 +02:00
Miroslav Stampar
f494004f44
Switching to the getSafeExString (where it can be used)
2015-09-10 15:51:33 +02:00
Miroslav Stampar
7a261ef447
Just in case commit related to the aee4c93c8b
2015-09-10 15:19:33 +02:00
Miroslav Stampar
00955a7eb5
Miniscule commit
2015-09-10 15:19:09 +02:00
Miroslav Stampar
5172999b00
Updating the doc/THANKS ( #1402 )
2015-09-10 15:09:24 +02:00
Miroslav Stampar
b06a34ab1a
Another update for #1402
2015-09-10 15:06:07 +02:00
Miroslav Stampar
2453b02b63
Update for #1402
2015-09-10 15:01:30 +02:00
Miroslav Stampar
b3fdbe24c2
Merge pull request #1402 from daremon/api-client
...
Minimal API client
2015-09-10 12:03:25 +02:00
Miroslav Stampar
263665637e
Minor bug fix
2015-09-10 11:34:03 +02:00
daremon
a29a3a4e5c
Minimal API client
2015-09-09 16:14:04 +03:00
Miroslav Stampar
72cf9041bf
Fixes #1401
2015-09-09 14:46:06 +02:00
Miroslav Stampar
90329a8b01
Minor patch
2015-09-09 11:53:44 +02:00
Miroslav Stampar
b6206692e0
Fixes #1392
2015-09-08 11:53:29 +02:00
Miroslav Stampar
c1f829d131
Removing last remnants of bad handling the exceptions as strings
2015-09-08 11:15:31 +02:00
Miroslav Stampar
e59a220199
Fixes #1393
2015-09-08 11:10:47 +02:00
Miroslav Stampar
924e31c414
Fixes #1394
2015-09-08 11:04:36 +02:00
Miroslav Stampar
28a60f5be2
Fixes #1391
2015-09-06 20:22:07 +02:00
Miroslav Stampar
aee4c93c8b
Fixes #1384
2015-09-03 10:32:45 +02:00
Miroslav Stampar
d06646e412
Miniscule change
2015-09-03 10:32:22 +02:00
Miroslav Stampar
51a4cb04a5
Another minor language patch
2015-09-03 10:26:46 +02:00
Miroslav Stampar
41c21ab7f2
Minor consistency patch
2015-09-03 10:19:59 +02:00
Miroslav Stampar
69563fc24f
Language fix
2015-09-03 10:18:00 +02:00
Miroslav Stampar
7511023bc2
Fixes #1385
2015-09-03 10:11:36 +02:00
Miroslav Stampar
fb5a75c9ad
Removing leftover
2015-08-31 14:50:51 +02:00
Miroslav Stampar
401564898d
Adding support for 'empty' POST body (if forced by --method)
2015-08-31 14:43:41 +02:00
Miroslav Stampar
265a78b455
Fixes #1379
2015-08-31 14:27:47 +02:00
Miroslav Stampar
d70215ad6c
Fixes #1237
2015-08-31 10:24:05 +02:00
Miroslav Stampar
d2a9c7584f
Minor patch
2015-08-31 09:51:35 +02:00
Miroslav Stampar
50d39d0252
Closes #1372
2015-08-30 23:15:50 +02:00
Miroslav Stampar
89292ce1f9
Closes #1376
2015-08-30 22:52:24 +02:00
Miroslav Stampar
6a01d2e430
Fixes #1366
2015-08-30 02:13:07 +02:00
Miroslav Stampar
737a37bfda
Fixes #1367
2015-08-30 01:58:43 +02:00
Miroslav Stampar
06c8704179
Fixes #1365
2015-08-28 15:30:28 +02:00
Miroslav Stampar
ee22c477db
Minor patch for #1363
2015-08-28 10:59:12 +02:00
Miroslav Stampar
61b33f24d4
Implements #1363
2015-08-28 10:52:36 +02:00
Miroslav Stampar
43f3900ffe
Fixes #1362
2015-08-27 12:25:25 +02:00
Miroslav Stampar
1cf012521d
Minor refactoring
2015-08-26 16:18:03 +02:00
Miroslav Stampar
a33b0454cd
Implementation for an Issue #1360
2015-08-26 15:26:16 +02:00
Miroslav Stampar
2c2f83f67b
Minor code consistency patch
2015-08-26 11:30:48 +02:00
Miroslav Stampar
1f5e6606a7
Fixes #1357
2015-08-25 02:03:56 +02:00
Miroslav Stampar
76c8ce0e70
More flexible --sql-file
2015-08-23 22:54:08 +02:00
Miroslav Stampar
337eb9861a
Fixes #1347
2015-08-23 22:11:59 +02:00
Miroslav Stampar
690347a170
Bug fix (non-ASCII chars in command line caused gibberish in unhandled messages)
2015-08-23 21:48:31 +02:00
Miroslav Stampar
9fb0eb3dd7
Blank removal
2015-08-23 21:41:59 +02:00
Miroslav Stampar
1204141278
Fixes #1350
2015-08-23 21:09:20 +02:00
Miroslav Stampar
fef8f20565
Minor reporting patch
2015-08-23 20:27:14 +02:00
Miroslav Stampar
b8f2c2bf8e
Merge pull request #1351 from KxCode/patch-1
...
fix removeDynamicContent bug
2015-08-23 20:13:39 +02:00
KingX
3ebb3e6f4f
fix removeDynamicContent bug
...
double re.escape() in "findDynamicContent" function and "removeDynamicContent" function leads an bug in finding dynamic content,
2015-08-22 14:05:03 +08:00
Miroslav Stampar
f609158d1b
Adding new error message (when short options carry illegal '=')
2015-08-19 21:00:16 +02:00
Miroslav Stampar
383316fcb3
Fixing issues caused by 9ad1d122f4 (better approach)
2015-08-18 22:48:55 +02:00
Miroslav Stampar
8806ce72c1
Patch for an Issue #1341
2015-08-18 22:03:42 +02:00
Miroslav Stampar
54d65328bc
Patch for negative logic (e.g. OR) cases (reported privately)
2015-08-18 03:09:01 +02:00
Miroslav Stampar
023def3203
Fixes #1336
2015-08-16 23:47:11 +02:00
Miroslav Stampar
c9d1c4d7b1
Fixes #1337
2015-08-16 23:29:39 +02:00
Miroslav Stampar
713d5384bc
Potential patch for an Issue #1337
2015-08-16 23:15:04 +02:00
Miroslav Stampar
310d79b8f1
Adding special variable 'lastPage' to the eval code (by request from ML)
2015-08-14 23:29:31 +02:00
Miroslav Stampar
b010fda695
Switch --save becomes an option (taking file path where to save config file)
2015-08-14 22:49:32 +02:00
Miroslav Stampar
f83de446f7
Merge pull request #1330 from flsf/master
...
Minor change
2015-08-14 22:38:02 +02:00
flsf
9adefb3ffd
Minor change
2015-08-14 16:18:51 +08:00
Miroslav Stampar
2c1cde0f59
Minor fix (reported over ML - ignore saving of conf.saveCmdline)
2015-08-13 17:21:36 +02:00
Miroslav Stampar
8ea8b168b1
Minor cosmetics
2015-08-13 17:10:35 +02:00
Miroslav Stampar
9ad1d122f4
Minor patch (Issue #1327 )
2015-08-12 22:09:31 +02:00
Miroslav Stampar
e5863d8b89
Minor patch
2015-08-12 21:43:13 +02:00
Miroslav Stampar
236b774f9a
Merge pull request #1328 from jerrypy/master
...
fixed open pipe and zoombie problems
2015-08-12 21:26:02 +02:00
Jiang Jie
1ac27e9305
fixed pipe and zoombie problems
...
1.we don't need stdin here, and it'll cause OSError: too many openfiles problem.
2. after using /scan/taskid/stop , process turned into a zoombie, need add wait()
2015-08-12 16:25:33 +08:00
Miroslav Stampar
62f35698ee
Bug fix (ML) - when cookies have blank expiration time
2015-08-06 13:07:16 +02:00
Miroslav Stampar
ce64d9797e
Fixes #1322
2015-08-04 11:10:15 +02:00
Miroslav Stampar
971f59a27e
Minor update
2015-08-04 10:28:43 +02:00
Miroslav Stampar
c5f3c0cc32
Fixes #1324
2015-08-03 17:21:35 +02:00
Miroslav Stampar
e623ee66ad
Better approach for #1320
2015-07-30 23:29:31 +02:00
Miroslav Stampar
bcb25823e6
Fixes #1320
2015-07-30 23:19:38 +02:00
Miroslav Stampar
301aca57e6
Fixes #1319
2015-07-29 10:00:15 +02:00
Miroslav Stampar
ba86153d29
Fixes #1318
2015-07-28 09:33:40 +02:00
Miroslav Stampar
401905b2dd
Minor improvement to UNION file write
2015-07-26 17:02:46 +02:00
Miroslav Stampar
64b45f2ac2
Fixes #1316
2015-07-26 16:34:11 +02:00
Miroslav Stampar
e3553ae893
Missing import
2015-07-26 16:19:44 +02:00
Miroslav Stampar
b0bc3149f9
Fixes #1315
2015-07-26 16:18:41 +02:00
Miroslav Stampar
e7af081447
Minor patch
2015-07-26 16:08:30 +02:00
Miroslav Stampar
314df093f1
Fixes #1314
2015-07-26 16:06:01 +02:00
Miroslav Stampar
ff6b62adf3
Important additional patch for #1170 (for PgSQL >= 9.0)
2015-07-24 15:15:41 +02:00
Miroslav Stampar
b6ea2fdb07
Fixes #1170
2015-07-24 14:56:45 +02:00
Miroslav Stampar
8df3d7a6fa
Minor enhancement for beep
2015-07-24 12:11:12 +02:00
Miroslav Stampar
a905b8d8f5
Fixes #1312
2015-07-23 10:07:21 +02:00
Miroslav Stampar
58002c5057
Minor cosmetics
2015-07-23 09:55:59 +02:00
Miroslav Stampar
cece2cb12d
Minor cosmetics
2015-07-23 00:42:29 +02:00
Miroslav Stampar
358651b19c
Fixes #1313
2015-07-23 00:41:03 +02:00
Miroslav Stampar
75ed5f767c
Fixes #1309
2015-07-20 17:03:20 +02:00
Miroslav Stampar
2afb5687f6
Fixes #1307
2015-07-20 15:47:27 +02:00
Miroslav Stampar
21e8182ac6
Fixes #1305
2015-07-18 17:01:34 +02:00
Miroslav Stampar
a7c4400cc9
Fixes #1304
2015-07-17 14:20:51 +02:00
Miroslav Stampar
00f190fc92
Fixes #1303
2015-07-17 10:14:35 +02:00
Miroslav Stampar
49212ec920
Fixes #1302
2015-07-17 09:56:24 +02:00
Miroslav Stampar
1aafe85a3a
Fixes #1299
2015-07-15 11:15:06 +02:00
Miroslav Stampar
fdc8e664df
Updating --beep functionality (ML request)
2015-07-13 23:55:46 +02:00
Miroslav Stampar
16f8e4c8ba
Removing unused imports
2015-07-12 12:25:02 +02:00
Miroslav Stampar
ffd9498827
Bug fix
2015-07-12 12:24:06 +02:00
Miroslav Stampar
4800ea7311
Bug fix
2015-07-12 12:17:26 +02:00
Miroslav Stampar
a20da7a677
Patch for automatic reporting (GitHub has robots)
2015-07-12 12:05:19 +02:00
Miroslav Stampar
fa303ef8b1
Minor update
2015-07-10 16:39:18 +02:00
Miroslav Stampar
10f8c6a0b6
Introducing --offline switch (to perform session only lookups)
2015-07-10 16:10:24 +02:00
Miroslav Stampar
9bdbdc136f
Minor cosmetics update
2015-07-10 11:33:12 +02:00
Miroslav Stampar
0ba264bfa0
Minor patch
2015-07-10 09:51:11 +02:00
Miroslav Stampar
4baaa4a5ad
Minor improvement
2015-07-10 09:24:14 +02:00
Miroslav Stampar
9ff115ce71
Minor patch
2015-07-10 01:33:53 +02:00
Miroslav Stampar
02470ea683
Further decreasing number of testing payloads
2015-07-10 01:19:46 +02:00
Miroslav Stampar
48b627f3ff
Prevent double tests (e.g. in same final tests where suffix is cut by the comment)
2015-07-10 00:54:02 +02:00
Miroslav Stampar
ca2f63c672
Test speed up in case of boolean based blind
2015-07-10 00:37:59 +02:00
Miroslav Stampar
3a5cc98976
-Z is/are a pseudo-option (just like -H) expanded during the run
2015-07-07 09:27:18 +02:00
Miroslav Stampar
2080fcaa37
Fixes #1293
2015-07-07 09:24:16 +02:00
Miroslav Stampar
f488377001
Fixes #1293
2015-07-07 08:47:07 +02:00
Miroslav Stampar
6a1b3895f9
Patch for an Issue #1285
2015-07-06 11:50:59 +02:00
Miroslav Stampar
96327b6701
Fixes #1290
2015-07-05 01:47:01 +02:00
Miroslav Stampar
166dc98e81
Minor patch
2015-07-05 00:03:29 +02:00
Miroslav Stampar
1f71d809d4
Fixes #1288
2015-07-03 08:55:33 +02:00
Miroslav Stampar
7b95a2d80d
Patch for an Issue #1280
2015-06-29 10:05:16 +02:00
Miroslav Stampar
8b63ee9bc3
Minor update for #1281
2015-06-29 01:12:14 +02:00
Miroslav Stampar
97244f5e5e
Fixes #1279
2015-06-29 00:20:35 +02:00
Miroslav Stampar
b212321c07
Fixes #1278
2015-06-26 10:30:53 +02:00
Miroslav Stampar
b02be9674f
Fixes #1277
2015-06-26 10:11:34 +02:00
Miroslav Stampar
7d418af274
Fix for a bug reported privately by email
2015-06-22 16:28:35 +02:00
Miroslav Stampar
9e5ef094a3
Closes #1270
2015-06-16 22:20:21 +02:00
Miroslav Stampar
e4b23c9beb
Minor fix regarding POST redirects (ML)
2015-06-16 12:00:56 +02:00
Miroslav Stampar
04c1d439a7
Minor patch for #1260
2015-06-05 17:18:21 +02:00
Miroslav Stampar
8d7e915af7
Minor patch for #1260
2015-06-05 17:02:56 +02:00
Miroslav Stampar
ebc2a729c9
Adding compiled UDFs for PostgreSQL 32-bit (9.2, 9.3 and 9.4)
2015-06-05 16:24:28 +02:00
Miroslav Stampar
419c55898b
Adding compiled UDFs for PostgreSQL 64-bit (9.1, 9.2, 9.3 and 9.4)
2015-06-05 15:23:39 +02:00
Miroslav Stampar
87b5262ef7
Minor patch
2015-06-01 14:18:21 +02:00
Miroslav Stampar
515ba5fb31
Minor patch for an Issue #1252
2015-06-01 11:13:02 +02:00
Miroslav Stampar
ec87d8ebda
Adding a support for SNI (Issue #1256 )
2015-06-01 10:45:16 +02:00
Miroslav Stampar
341d2a6028
Minor fix for (hidden) switch '--dummy'
2015-05-29 17:30:02 +02:00
Miroslav Stampar
08caca387b
Minor patch of automatic WAF heuristic check
2015-05-29 16:01:41 +02:00
Miroslav Stampar
c62b0f7e68
New tamper script
2015-05-28 23:49:44 +02:00
Miroslav Stampar
699c965bc0
Fixes #1248
2015-05-19 18:40:45 +02:00
Miroslav Stampar
17bfda1b9c
Adding new switch ('--skip-static')
2015-05-18 20:57:15 +02:00
Miroslav Stampar
e8f87bfa41
Minor patches related to the #1206
2015-05-11 11:01:21 +02:00
Miroslav Stampar
91bc02e3ba
Fixes related to the #1206
2015-05-11 10:56:10 +02:00
Miroslav Stampar
c8aac19f75
Merge branch 'RicterZ-master'
2015-05-11 10:11:43 +02:00
Miroslav Stampar
9010e157e9
Conflict fix
2015-05-11 10:11:33 +02:00
Miroslav Stampar
5b8df7984c
Minor update (for Windows-31j charset)
2015-05-09 14:32:55 +02:00
Miroslav Stampar
4b2ff4339a
Fixes #1243
2015-05-07 12:36:23 +02:00
Miroslav Stampar
18e62fd507
Fix for an Issue #1240
2015-05-05 14:36:21 +02:00
Miroslav Stampar
84ba3d45c1
Patch for an Issue #1238
2015-05-04 21:47:10 +02:00
Miroslav Stampar
5ee7fd785a
Fixes #1235
2015-05-01 00:48:08 +02:00
Miroslav Stampar
03f32ae2b6
Merge of an Issue #1227
2015-04-22 17:21:55 +02:00
Miroslav Stampar
a94dcf94e9
Patch for an Issue #1226đ
2015-04-22 16:41:20 +02:00
Miroslav Stampar
bb98894dc1
Adding option --safe-req
2015-04-22 16:28:54 +02:00
Miroslav Stampar
4ded9a9966
Small patch for existing option validation
2015-04-22 15:32:14 +02:00
Miroslav Stampar
77c96de4ea
Minor patch related to the last commit
2015-04-22 10:33:22 +02:00
Miroslav Stampar
95b52a02ec
Minor patch for custom injection into HTTP Authorization header
2015-04-22 10:28:16 +02:00
Miroslav Stampar
c5138d4696
Minor refactoring
2015-04-21 00:02:47 +02:00
Miroslav Stampar
349dfbf2ae
Adding an option --safe-post
2015-04-20 23:55:59 +02:00
Miroslav Stampar
7517db76d1
Minor fix for SQLite's schema parsing
2015-04-16 18:40:43 +02:00
Miroslav Stampar
dbfa8f1cfc
Fix for a bug reported by the user (conf.scheme/conf.hostname/conf.port were None in multiple targets mode)
2015-04-14 11:05:17 +02:00
Miroslav Stampar
0e4800f73c
Changing default answer for sitemap checking to N
2015-04-14 09:30:01 +02:00
Miroslav Stampar
1e7f2d6da2
Implements #1215
2015-04-06 22:07:22 +02:00
Miroslav Stampar
26bec7219d
Update for an Issue #1184
2015-03-31 07:33:50 +02:00
Miroslav Stampar
c35fa63a48
Fixes #1212
2015-03-30 11:58:09 +02:00
Miroslav Stampar
99c1cc9937
Fixes #1208
2015-03-26 17:17:46 +01:00
Miroslav Stampar
a19bccc84f
Fixes #1205
2015-03-26 15:31:29 +01:00
Miroslav Stampar
770cfb6102
Removing test print
2015-03-26 15:20:54 +01:00
Miroslav Stampar
fc0186e029
Minor update
2015-03-26 12:39:44 +01:00
Miroslav Stampar
5dfd3ef1e4
Another update
2015-03-26 12:25:32 +01:00
Miroslav Stampar
3be7a447a5
Update
2015-03-26 12:22:49 +01:00
Miroslav Stampar
e3130c1ba1
Implements #1207
2015-03-26 11:57:51 +01:00
Miroslav Stampar
7587528ebd
Fixes #1202
2015-03-26 11:40:19 +01:00
Miroslav Stampar
7b2c27fa8d
One more update for #1200 (better implementation)
2015-03-26 01:22:16 +01:00
Miroslav Stampar
ac74184422
Fixes #1200
2015-03-25 23:43:48 +01:00
ricterz
bbfdb02a0e
fix mandatorily depend of websocket #1198
2015-03-24 22:25:16 +08:00
ricterz
811f5c11c6
remove Host header field and add cookie support #1198
2015-03-24 18:50:57 +08:00
ricterz
9b5dcbbbb2
modified error handle #1198
2015-03-24 18:21:50 +08:00
ricterz
78dbe080d7
determine whether it's websocket when connect #1198
2015-03-24 17:19:37 +08:00
ricterz
50fd6ce7f7
add websocket support for parse url #1198
2015-03-24 10:30:38 +08:00
Miroslav Stampar
05a496c275
Fixes #1196
2015-03-20 00:56:52 +01:00
Bernardo Damele
9eb7a0a0f2
enhanced time-based payloads - issue #1169
2015-03-19 12:09:43 +00:00
Bernardo Damele
43f6cb1508
some more boundaries
2015-03-19 12:07:26 +00:00
Bernardo Damele
204ee1db39
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2015-03-19 12:06:36 +00:00
Miroslav Stampar
f5df80527c
Fixes #1195
2015-03-18 14:26:51 +01:00
Bernardo Damele
865c3852ea
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2015-03-16 09:00:59 +00:00
Miroslav Stampar
25b23750e8
Bug fix for crawling over non-80 port
2015-03-12 11:49:52 +01:00
Bernardo Damele
0a0c3edf06
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2015-03-10 09:25:54 +00:00
Miroslav Stampar
adc8ac267d
Fixes #1190
2015-03-10 09:23:26 +01:00
Miroslav Stampar
9bd41ed99d
Fixes #1189
2015-03-09 22:02:20 +01:00
Bernardo Damele
2bdf121915
cleanup
2015-03-04 13:36:09 +00:00
Miroslav Stampar
02fb5058c2
Merge pull request #1186 from cvwillegen/master
...
Fix some spelling errors in help texts (through -> thorough)
2015-03-04 13:57:06 +01:00
Christ van Willegen
80fb2e29cc
Fix some spelling errors in help texts (through -> thorough)
2015-03-04 13:31:29 +01:00
Bernardo Damele A. G.
b2fca35c36
consolidated some time-based blind payloads - issue #1169
2015-03-03 14:22:20 +00:00
Bernardo Damele
e13bbe2e87
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2015-03-03 14:19:48 +00:00
Bernardo Damele
37ca0a95f1
consolidated stacked queries payloads - issue #1169
2015-03-03 14:19:36 +00:00
Bernardo Damele
849ca3da3d
added a newline
2015-03-03 14:18:53 +00:00
Miroslav Stampar
3347fc25ca
Fixes #1185
2015-03-03 15:10:06 +01:00
Miroslav Stampar
3f6c3b40dd
Minor update (not overriding user given 'Accept-Encoding' header value)
2015-03-03 14:37:36 +01:00
Bernardo Damele
8281fe48e5
bug fix: test for boundaries with high levels if the test was extended
2015-03-01 11:02:05 +00:00
Bernardo Damele
260643241a
prioritized fingerprinted DBMS to error-based and user provided one
2015-02-27 14:19:30 +00:00
Bernardo Damele
2f08c8b666
bug fix: do not skil heuristic check if previous page (test for dynamicity) had DBMS message. Code cleanup
2015-02-27 13:57:28 +00:00
Miroslav Stampar
ee11292f87
Update of doc/THANKS
2015-02-25 10:33:54 +01:00
Miroslav Stampar
33429f443c
Minor update
2015-02-25 10:31:27 +01:00
Miroslav Stampar
dde400ab8f
More suitable version of 6bcc95a (suggested by user)
2015-02-25 10:19:51 +01:00
Miroslav Stampar
b74edf9664
Fixes #1175
2015-02-25 10:16:01 +01:00
Miroslav Stampar
6bcc95a20d
Restricting evaluated code variable names to Python valid characters ([_0-9a-zA-Z])
2015-02-24 15:05:44 +01:00
Miroslav Stampar
e35c7fbb7a
Fixes #1172
2015-02-22 13:41:54 +01:00
Bernardo Damele
475cc8b24b
trivial code cleanup
2015-02-21 13:12:30 +00:00
Bernardo Damele
383929c0c2
if the user forces the DBMS, then sort the tests accordingly to perform first the DBMS-specific tests, then the others
2015-02-21 13:12:03 +00:00
Bernardo Damele
d235ee375b
code cleanup
2015-02-21 12:59:44 +00:00
Bernardo Damele
8be24d3e9b
minor enhancement, prefer intersect() each time DBMS values are comfronted
2015-02-21 12:59:27 +00:00
Bernardo Damele
388c0dfd77
trivial layout fix
2015-02-21 12:57:49 +00:00
Bernardo Damele
21c1ae427b
swapped generic and MySQL-specific UNION payloads - issue #1169
2015-02-21 12:57:28 +00:00
Bernardo Damele
ef9d4b58ae
minor signature for PHP pgsql functions
2015-02-21 02:24:03 +00:00
Bernardo Damele
52dd92748a
rework some of the logic of the detection phase based on identified DBMS along the way
2015-02-21 02:23:42 +00:00
Bernardo Damele
4f939b5719
avoid false positive message when extensive heuristic check is performed following detection of boolean blind injection detection: do only heuristic DBMS fingerprint for DBMS specific tables
2015-02-20 18:36:34 +00:00
Bernardo Damele
4bbf168b18
Minor titles fix
2015-02-20 18:35:13 +00:00
Bernardo Damele
ab6cc271d3
Major consistency rework of error-based payloads - issue #1169
2015-02-20 18:34:47 +00:00
Bernardo Damele
9fed41ddc2
Major consistency rework of boolean payloads - issue #1169
2015-02-20 18:34:23 +00:00
Bernardo Damele
2d886011c8
Consistency in enums
2015-02-20 18:33:04 +00:00
Bernardo Damele
1ecb921ba7
Consistency in enums
2015-02-20 18:31:47 +00:00
Bernardo Damele
214b9360e9
Minor fix to check for inline query payloads regardless of previously identified payloads and code cleanup
2015-02-20 18:30:42 +00:00
Bernardo Damele
3b3205c532
Minor stacked queries and time-based payloads cleanup - issue #1169
2015-02-20 15:44:06 +00:00
Bernardo Damele
79d4d970a5
trivial code cleanup
2015-02-20 15:42:28 +00:00
Bernardo Damele
5b65d2e133
more consistency of boolean blind payloads - issue #1169
2015-02-20 11:34:16 +00:00
Bernardo Damele
201b605f9b
Minor fix and consistency: do not ask to include all tests if level and risk are at the max settings already
2015-02-20 10:21:44 +00:00
Bernardo Damele
f547a776d8
consolidating blind based payloads - issue #1169
2015-02-19 16:42:26 +00:00
Bernardo Damele
4195f770a3
removing one unnecessary character from stacked payloads
2015-02-19 16:41:55 +00:00
Bernardo Damele
1e9586c90b
minor layout fix
2015-02-19 16:18:16 +00:00
Bernardo Damele
6cc092b926
split payloads in different files
2015-02-18 10:13:44 +00:00
Bernardo Damele
daa8e0d8c5
minor fix
2015-02-18 10:13:28 +00:00
Bernardo Damele
560bc7cc28
minor fixes
2015-02-18 09:51:07 +00:00
Bernardo Damele
c51ecf33f3
ported the recent MySQL time-based payload (introduced with 66c2a79397) to other techniques and conditions
2015-02-18 09:45:44 +00:00
Miroslav Stampar
1636088b75
Minor update
2015-02-16 11:48:53 +01:00
Bernardo Damele
32373996ee
standard message
2015-02-15 20:53:40 +00:00
Bernardo Damele
e17d212c23
bug fix introduced with 863d5a6281
2015-02-15 20:07:52 +00:00
Bernardo Damele
84349a370a
minor code cleanup
2015-02-15 19:51:07 +00:00
Bernardo Damele
32ab52b8ca
code refactoring: split boundaries and payloads XML files
2015-02-15 16:31:35 +00:00
Bernardo Damele
863d5a6281
--test-filter now ignores values of --risk and --level
2015-02-15 16:28:37 +00:00
Miroslav Stampar
2e5c11e427
Closes #1163
2015-02-13 10:59:03 +01:00
Miroslav Stampar
b1d13d1e7d
Patch for an Issue #1158
2015-02-06 09:05:41 +01:00
Miroslav Stampar
247384858e
Patch for an Issue #1159 (undo commit with single-quotes problem on windows)
2015-02-04 16:21:21 +01:00
Miroslav Stampar
38011743bb
Patch for an Issue #1157
2015-02-04 15:01:19 +01:00
Bernardo Damele
66c2a79397
added a time-based payload for MySQL when the simpler AND SLEEP(X) does not work
2015-02-03 15:14:41 +00:00
Miroslav Stampar
eecc0b924b
Patch for an Issue #1148
2015-02-03 10:06:00 +01:00
Miroslav Stampar
2af2aef43e
Minor patch for masking sensitive information (when formation -u=... is used)
2015-02-03 09:48:05 +01:00
Miroslav Stampar
59f0da369d
Patch for a bug reported via ML (Accept header ignored in --headers)
2015-02-02 22:07:16 +01:00
Miroslav Stampar
8b135e45bd
Patch for an Issue #1147
2015-02-02 22:05:31 +01:00
Miroslav Stampar
bf1c08a8a6
Bug fix
2015-01-30 22:43:40 +01:00
Miroslav Stampar
2e9bf47703
Heuristic check for WAF/IDS/IPS is now prone to tamper functions (Issue #1145 )
2015-01-30 22:12:35 +01:00
Miroslav Stampar
9e90e357cf
Patch for an Issue #1146
2015-01-30 21:59:03 +01:00
Miroslav Stampar
9563e429d3
Removal of fun code
2015-01-30 21:49:22 +01:00
Miroslav Stampar
9f679a952f
Minor update
2015-01-29 10:44:36 +01:00
Miroslav Stampar
024c500d8e
Minor fix
2015-01-28 00:54:39 +01:00
Miroslav Stampar
5400bb2c95
Patch for an Issue #1142
2015-01-28 00:52:40 +01:00
Miroslav Stampar
fd632e5ada
Update for unhandled exception mechanism (BADA)
2015-01-26 09:09:38 +01:00
Miroslav Stampar
eb548959b3
Minor update
2015-01-26 08:59:10 +01:00
Miroslav Stampar
f0eac38ab4
Minor fix
2015-01-26 08:48:37 +01:00
Miroslav Stampar
ae95fd91c2
Implementation for an Issue #1135
2015-01-24 23:49:33 +01:00
Miroslav Stampar
32bf2dbe6d
Patch for an Issue #1133
2015-01-23 23:00:28 +01:00
Miroslav Stampar
779db7cbc3
Minor enhancement
2015-01-22 09:17:45 +01:00
Miroslav Stampar
b7cfaa6ca5
Minor style update
2015-01-22 08:55:37 +01:00
Miroslav Stampar
2655b078d0
Patch for an Issue #1127
2015-01-22 08:52:15 +01:00
Miroslav Stampar
02b3eb941f
Patch for an Issue #1124
2015-01-21 09:26:30 +01:00
Miroslav Stampar
cd743ab098
Minor update
2015-01-21 09:12:12 +01:00
Miroslav Stampar
9f4a32ca2b
Automatically checking for sitemap existence in case of --crawl
2015-01-20 10:03:35 +01:00
Miroslav Stampar
a603002acd
Adding a choice to automatically turn on --identify-waf if protection has been detected
2015-01-20 09:38:18 +01:00
Miroslav Stampar
a66b0c91bb
Patch for an Issue #1120
2015-01-19 09:19:30 +01:00
Miroslav Stampar
393659ffbf
Patch for an Issue #1121
2015-01-19 09:17:16 +01:00
Miroslav Stampar
e73ac6c8e3
Minor patch on request of an user
2015-01-17 21:47:57 +01:00
Miroslav Stampar
c2b2ccd2b5
Minor bug fix
2015-01-17 17:31:00 +01:00
Miroslav Stampar
da737d23ed
Fixing a leftover for #1117
2015-01-15 17:34:14 +01:00
Miroslav Stampar
20a9d94f56
Patch for an Issue #1117
2015-01-15 17:32:07 +01:00
Miroslav Stampar
1dd2b7aceb
Important fix for dumping location of databases/tables with international letters
2015-01-15 14:01:19 +01:00
Miroslav Stampar
ccbe424e23
Patch for an Issue #1115
2015-01-15 12:42:32 +01:00
Miroslav Stampar
54e9a1fb2d
Minor style update
2015-01-14 16:11:55 +01:00
Miroslav Stampar
570d30789b
Patch for an Issue #1113
2015-01-14 14:20:33 +01:00
Miroslav Stampar
c8787e0404
Merge pull request #1112 from all3g/master
...
datatype.py
2015-01-14 11:53:46 +01:00
nixawk
7388c3bf49
datatype.py
2015-01-14 09:40:24 +00:00
Miroslav Stampar
7e7513aa5e
Patch for an Issue #1107
2015-01-14 05:30:08 +01:00
Miroslav Stampar
f9a9ededb1
Patch for an Issue #1106
2015-01-14 05:16:32 +01:00
Miroslav Stampar
06ff8b3a16
Patch for an Issue #1105
2015-01-13 10:33:51 +01:00
Miroslav Stampar
8e03f4db0f
Patch for an Issue #1062
2015-01-09 15:33:53 +01:00
Miroslav Stampar
f96f33a984
Fix for an Issue #1100
2015-01-08 22:15:04 +01:00
Miroslav Stampar
7bcb3ce599
Patch for an Issue #1099
2015-01-08 09:22:47 +01:00
Miroslav Stampar
0c4d63fb00
Bug fix (reported by user over ML)
2015-01-08 09:00:21 +01:00
Miroslav Stampar
c8d4df6eba
Adding names to parameters in structured POST requests (e.g. JSON)
2015-01-07 22:09:40 +01:00
Miroslav Stampar
49982bce9c
Trivial update
2015-01-07 16:03:37 +01:00
Miroslav Stampar
450b3c93cb
Potential patch for an Issue #1093
2015-01-07 11:40:11 +01:00
Miroslav Stampar
30b9f3d556
Minor update
2015-01-07 10:53:57 +01:00
Miroslav Stampar
47af7dfe6a
Another minor patch
2015-01-07 10:49:15 +01:00
Miroslav Stampar
83add9fd9b
Minor patch
2015-01-07 10:46:06 +01:00
Miroslav Stampar
c4c4ac13fe
Better patch for an Issue #1095
2015-01-07 09:21:02 +01:00
Miroslav Stampar
2030311d50
Patch for an Issue #1095
2015-01-07 02:04:10 +01:00
Miroslav Stampar
5920d16cf6
Adding a warning message for deprecated switch '--check-waf+
2015-01-06 15:25:24 +01:00
Miroslav Stampar
45bdefd29b
Update of copyright
2015-01-06 15:02:16 +01:00
Miroslav Stampar
e976418d28
Minor patch
2015-01-06 14:58:05 +01:00
Miroslav Stampar
e41591c9c1
Adding new WAF script
2015-01-06 14:53:16 +01:00
Miroslav Stampar
8e680fb271
Minor update
2015-01-06 14:49:50 +01:00
Miroslav Stampar
cef5530255
Minor update
2015-01-06 14:41:19 +01:00
Miroslav Stampar
3d5ca1b25a
Minor update
2015-01-06 14:36:51 +01:00
Miroslav Stampar
abd429d48b
New waf script added
2015-01-06 14:11:53 +01:00
Miroslav Stampar
6fc41ca940
Heuristically checking for WAF/IDS/IPS by default
2015-01-06 14:01:47 +01:00
Miroslav Stampar
cd7d9edcbe
New waf file
2015-01-06 13:21:52 +01:00
Miroslav Stampar
c474c16b4a
Removing ML email address
2015-01-06 12:30:49 +01:00
Miroslav Stampar
7b144f03ea
Fix for an Issue #1092
2015-01-05 01:31:06 +01:00
Miroslav Stampar
beffe85d6c
Patch for an Issue #1085
2015-01-03 22:30:21 +01:00
Miroslav Stampar
f042a7392d
Patch for an Issue #1083
2014-12-31 17:10:45 +01:00
Miroslav Stampar
2985050fce
Minor patch
2014-12-30 16:07:08 +00:00
Miroslav Stampar
33508e3bae
Patch for an Issue #1077
2014-12-30 16:11:33 +01:00
Miroslav Stampar
41c2f889b2
Fix related to the SSLv3 disabling
2014-12-30 15:44:55 +01:00
Miroslav Stampar
d3c6cf1932
Patch for an Issue #1079
2014-12-30 14:14:47 +00:00
Miroslav Stampar
4f602daa5b
Minor patch
2014-12-30 09:35:56 +00:00
Miroslav Stampar
e383df8e29
Patch for an Issue #1073
2014-12-30 09:16:50 +00:00
Miroslav Stampar
e2edebd406
Patch for an Issue #1069
2014-12-30 09:04:41 +00:00
Miroslav Stampar
02d20ccd13
Patch for an Issue #1078
2014-12-30 08:48:50 +00:00
Miroslav Stampar
1e014de6be
Patch for an Issue #1066
2014-12-26 22:24:28 +01:00
Miroslav Stampar
bc91884c4d
Fix for an Issue #1065
2014-12-25 23:05:34 +01:00
Miroslav Stampar
45886cb9ca
Patch for an Issue #1060
2014-12-23 22:04:23 +01:00
Miroslav Stampar
483158c371
Minor style update
2014-12-23 09:07:33 +01:00
Miroslav Stampar
3c23d616e7
Adding a more user friendly (copy-pastable) client example for sqlmapapi client
2014-12-23 09:01:29 +01:00
Miroslav Stampar
59a3407322
Patch for an Issue #1057
2014-12-23 08:36:00 +01:00
Miroslav Stampar
f93bca4564
Patch for an Issue #1058
2014-12-23 08:23:40 +01:00
Miroslav Stampar
fc7dd2a9b9
Patch for an Issue #1056
2014-12-22 06:02:39 +01:00
Miroslav Stampar
3056fd4765
Fix for an Issue #1055
2014-12-22 05:56:48 +01:00
Miroslav Stampar
76f79ece13
run like --threads=20! will skip the maximum number of threads check
2014-12-21 05:15:42 +01:00
Miroslav Stampar
4f122ee008
Bug fix regarding a problem reported by user @blink2014
2014-12-20 00:23:31 +01:00
Miroslav Stampar
6cb76bcf85
Adding one new smart ass warning message
2014-12-19 15:48:54 +01:00
Miroslav Stampar
1ea2f5bfe2
Patch for an Issue #1052
2014-12-19 09:37:06 +01:00
Miroslav Stampar
cf3b02ee04
Proper fix for #1053
2014-12-19 09:26:01 +01:00
Miroslav Stampar
6972020faf
Bug fix for login-like SQLi (OR with 500 result)
2014-12-18 15:58:19 +01:00
Miroslav Stampar
0b91a6098f
Patch for an Issue #1050
2014-12-18 15:13:44 +01:00
Miroslav Stampar
8947f2df96
Patch for an Issue #1047
2014-12-17 23:07:27 +01:00
Miroslav Stampar
0cb7852754
Patch for an Issue #1046
2014-12-17 10:02:36 +01:00
Miroslav Stampar
180ede0cb3
Minor patch
2014-12-15 14:07:28 +01:00
Miroslav Stampar
9d06b71862
Minor revert
2014-12-15 13:51:00 +01:00
Miroslav Stampar
e6de92ce88
Minor patch (unicode related)
2014-12-15 13:36:08 +01:00
Miroslav Stampar
35c8e016a8
Minor patch
2014-12-15 13:26:15 +01:00
Miroslav Stampar
3f3a873b10
Merge pull request #1037 from flsf/master
...
fix comments error
2014-12-15 13:23:39 +01:00
flsf
21837f236f
fix comments error
2014-12-15 20:07:38 +08:00
Miroslav Stampar
c2f42214a3
Merge pull request #1033 from flsf/master
...
Update company name in parenthesis
2014-12-15 10:35:21 +01:00
flsf
872902b1c9
Update company name in parenthesis
2014-12-15 17:29:59 +08:00
Miroslav Stampar
f73204fffb
Update for an Issue #1029
2014-12-15 10:15:31 +01:00
Miroslav Stampar
8a2f281613
Merge pull request #1029 from flsf/master
...
add some waf scripts
2014-12-15 09:39:51 +01:00
Miroslav Stampar
4c6331daa6
Patch for an Issue #1028
2014-12-15 09:30:54 +01:00
Miroslav Stampar
e794c7f246
Patch for an Issue #1027
2014-12-15 09:13:13 +01:00
Miroslav Stampar
eb15a19532
Patch for an Issue #1032
2014-12-15 09:11:40 +01:00
Miroslav Stampar
ecbba4ea20
Patch for an Issue #1030
2014-12-15 07:18:47 +01:00
flsf
a56dcc1dc3
Adding new WAF script (safedog)
2014-12-15 03:23:06 +08:00
flsf
b90bbe18c8
Adding new WAF script (Baidu yunjiasu)
2014-12-15 03:19:23 +08:00
flsf
9d93180153
Adding new WAF script (Anquanbao)
2014-12-15 03:14:16 +08:00
flsf
e946315736
Adding new WAF script (360)
2014-12-15 03:12:53 +08:00
flsf
c995c5252f
Update of jiasule.py WAF script
2014-12-15 03:08:39 +08:00
Miroslav Stampar
e17e703e3e
Minor bug fix (for Windows nagging message about Unicode data)
2014-12-14 00:17:43 +01:00
Miroslav Stampar
fb645b90f7
Minor update
2014-12-14 00:14:18 +01:00
Miroslav Stampar
87f8753483
Fixing a problem with AV detection
2014-12-14 00:10:43 +01:00
Miroslav Stampar
b42a15d876
Minor patch related to the Issue #1025
2014-12-13 23:37:04 +01:00
Miroslav Stampar
5166675ff5
Patch for an Issue #1024
2014-12-13 23:32:18 +01:00
Miroslav Stampar
9c225557d1
Patch for an Issue #1020
2014-12-13 14:08:37 +01:00
Miroslav Stampar
25196b4572
Patch for an Issue #1021
2014-12-13 13:48:50 +01:00
Miroslav Stampar
84ba5f35ac
Minor update for #1022
2014-12-13 13:41:39 +01:00
Miroslav Stampar
fe58aff26c
Patch for an Issue #1019
2014-12-13 00:08:18 +01:00
Miroslav Stampar
650dfe9526
Patch for an Issue #1018
2014-12-12 14:54:47 +01:00
Miroslav Stampar
23d33bb5b5
Patch for an Issue #1017
2014-12-12 09:58:42 +01:00
Miroslav Stampar
bb4ac41ff7
Patch for an Issue #1016
2014-12-12 04:40:44 +01:00
Miroslav Stampar
785e3d0317
Patch for an Issue #1014
2014-12-11 13:29:42 +01:00
Miroslav Stampar
1e06e7c386
Adding a debug message during name resolution
2014-12-11 13:29:26 +01:00
Miroslav Stampar
6f211f9d3e
Patch for an Issue #1013
2014-12-11 00:35:51 +01:00
Miroslav Stampar
6d13b67822
Patch for an Issue #1012
2014-12-11 00:32:26 +01:00
Miroslav Stampar
2bcaae3a0b
Another just in case update for an Issue #1011
2014-12-11 00:14:35 +01:00
Miroslav Stampar
763f720675
Patch for an Issue #1011
2014-12-11 00:11:52 +01:00
Miroslav Stampar
10ed97b0df
Patch for an Issue #1010
2014-12-10 13:50:29 +01:00
Miroslav Stampar
ee20d98bca
Minor fix for --forms
2014-12-10 12:13:37 +01:00
Miroslav Stampar
d700e50b36
Minor update related to the Issue #993
2014-12-10 06:37:17 +01:00
Miroslav Stampar
a7b21a2f62
Rerun advice update
2014-12-09 09:02:06 +01:00
Miroslav Stampar
20c272b77d
More generic patch for an Issue #994
2014-12-07 16:14:48 +01:00
Miroslav Stampar
4e7f835eae
Patch for an Issue #994
2014-12-07 16:11:07 +01:00
Miroslav Stampar
0d931a7b09
Fix for an Issue #999
2014-12-07 15:55:22 +01:00
Miroslav Stampar
4325f21b58
Update for an Issue #996
2014-12-07 07:48:46 +01:00
Miroslav Stampar
ff0dd8eefe
Patch for an Issue #997
2014-12-06 21:40:52 +01:00
Miroslav Stampar
bd99470a4a
Minor update to cleanup properly new xp_cmdshell
2014-12-05 22:01:59 +01:00
Miroslav Stampar
d726050bc4
Patch for an Issue #991
2014-12-05 11:46:03 +01:00
Miroslav Stampar
034fae0f47
Patch for an Issue #992
2014-12-05 11:24:43 +01:00
Miroslav Stampar
7673f3e045
Minor style update
2014-12-05 11:15:33 +01:00
Miroslav Stampar
56965e3608
Patch for an Issue #990
2014-12-04 13:36:41 +01:00
Miroslav Stampar
9b32e69f26
Adding new WAF script (UrlScan)
2014-12-04 10:06:15 +01:00
Miroslav Stampar
a3507d65fd
Minor update
2014-12-04 09:34:37 +01:00
Miroslav Stampar
d3060f20d7
Minor improvement
2014-12-03 13:22:55 +01:00
Miroslav Stampar
aa95a05477
Minor update
2014-12-03 13:14:06 +01:00
Miroslav Stampar
17db587e2c
Adding some friendly warning messages (regarding blocking)
2014-12-03 10:06:21 +01:00
Miroslav Stampar
821e4bf507
Patch for an Issue #987
2014-12-03 08:46:02 +01:00
Miroslav Stampar
e4b00bdbcb
Patch for an Issue #983
2014-12-02 10:57:50 +01:00
Miroslav Stampar
2358e34bb8
Minor refactoring
2014-12-02 10:50:15 +01:00
Miroslav Stampar
636e0588d5
Patch for an Issue #981
2014-12-02 10:29:09 +01:00
Miroslav Stampar
e03aaa7542
Patch for an Issue #982
2014-12-02 10:23:10 +01:00
Miroslav Stampar
7a04595f5e
Added a reference url (http charset priority)
2014-12-01 11:15:45 +01:00
Miroslav Stampar
f71a65a9a0
Patch for an Issue #979
2014-12-01 00:29:25 +01:00
Miroslav Stampar
56b6bf72f4
Patch for an Issue #978
2014-11-29 23:33:24 +01:00
Miroslav Stampar
ab49fe6a39
New WAF script
2014-11-28 15:00:39 +01:00
Miroslav Stampar
f47b493a24
Minor update
2014-11-28 14:10:31 +01:00
Miroslav Stampar
2115fc1491
New WAF script
2014-11-28 14:03:53 +01:00
Miroslav Stampar
e8673b9acc
Update of modsecurity.py WAF script
2014-11-28 13:32:41 +01:00
Miroslav Stampar
0c99b79c60
Minor fix
2014-11-28 00:54:03 +01:00
Miroslav Stampar
605b126758
Patch for an Issue #976
2014-11-26 13:38:21 +01:00
Miroslav Stampar
8cd40f8917
Patch for an Issue #971
2014-11-25 13:54:26 +01:00
Miroslav Stampar
a0d95a8ec4
Refactoring of #952
2014-11-24 12:56:39 +01:00
Miroslav Stampar
27cd9e7064
Merge pull request #952 from Rexikon/patch-1
...
Update httpshandler.py, AttributeError PROTOCOL_SSLv3
2014-11-24 12:52:27 +01:00
Miroslav Stampar
816348f1ab
Patch for an Issue #963
2014-11-24 11:54:04 +01:00
Miroslav Stampar
05f7b1f121
Patch for an Issue #970
2014-11-24 10:55:19 +01:00
Miroslav Stampar
2f744139fc
Patch for an Issue #968
2014-11-24 10:13:56 +01:00
Miroslav Stampar
2284535267
Update for an Issue #963
2014-11-24 05:44:38 +01:00
Miroslav Stampar
69cdad4148
Patch for an Issue #958
2014-11-23 15:55:12 +01:00
Miroslav Stampar
28d6af6237
Minor update
2014-11-23 15:42:41 +01:00
Miroslav Stampar
f853f8973f
Minor refactorign
2014-11-23 15:41:24 +01:00
Miroslav Stampar
080a873922
Patch for an Issue #964
2014-11-23 15:39:08 +01:00
Miroslav Stampar
40eb1973d7
Patch for an Issue #961
2014-11-23 15:33:04 +01:00
Miroslav Stampar
5c182a0ec4
Update for an Issue #431
2014-11-21 11:33:57 +01:00
Miroslav Stampar
f0802c6fb9
Update for an Issue #431
2014-11-21 11:20:54 +01:00
Miroslav Stampar
1fc4d0e3c4
Update for an Issue #431
2014-11-21 10:31:55 +01:00
Miroslav Stampar
cf2d5fd453
Update for an Issue #431
2014-11-21 09:41:49 +01:00
Miroslav Stampar
34ce774acd
Patch for an Issue #956
2014-11-21 09:41:49 +01:00
Miroslav Stampar
1a8b58fca6
Minor update
2014-11-20 16:42:06 +01:00
Miroslav Stampar
f8a8cbf9a6
Storing crawling results to a temporary file (for eventual further processing)
2014-11-20 16:29:17 +01:00
Miroslav Stampar
d3551631c4
Minor update
2014-11-20 16:10:25 +01:00
Miroslav Stampar
484fa61afc
Patch for an Issue #954
2014-11-20 15:08:08 +01:00
Miroslav Stampar
ee8b3ee664
Patch for an Issue #953
2014-11-20 09:49:04 +01:00
Rexikon
4da20679ee
Update httpshandler.py
...
ssl.PROTOCOL_SSLv3 removed
affecting error: AttributeError: 'module' object has no attribute 'PROTOCOL_SSLv3'
2014-11-19 16:36:30 +01:00
Miroslav Stampar
80b9fc4821
Minor fix
2014-11-19 09:21:52 +01:00
Miroslav Stampar
05d5342f20
Update and patch for an Issue #2
2014-11-17 11:50:05 +01:00
Miroslav Stampar
733e06e31f
Patch for an Issue #944
2014-11-16 14:25:44 +01:00
Miroslav Stampar
bb56eb583a
Minor update
2014-11-16 13:34:35 +01:00
Miroslav Stampar
a827453eb7
Update for an Issue #907
2014-11-16 08:31:01 +01:00
Miroslav Stampar
d8d9678947
Patch for an Issue #935
2014-11-14 00:21:04 +01:00
Miroslav Stampar
74eacf95fd
Patch for an Issue #929
2014-11-13 10:52:33 +01:00
Miroslav Stampar
671facc6d9
Patch for an Issue #930
2014-11-13 10:28:38 +01:00
Miroslav Stampar
d0afa7f325
Bug fix for not displaying proper version in unhandled exception win cases
2014-11-12 11:53:42 +01:00
Miroslav Stampar
c98bd521c5
Patch for an Issue #923
2014-11-11 11:53:51 +01:00
Miroslav Stampar
06e6d2aaeb
Patch for an Issue #921
2014-11-11 11:38:14 +01:00
Miroslav Stampar
c5df45a14f
Minor bug fix (skipping HTML decoding in heuristic mode)
2014-11-11 11:23:14 +01:00
Miroslav Stampar
dfa8e0456d
Potential patch for an Issue #914
2014-11-10 14:51:31 +01:00
Miroslav Stampar
cdbfb17408
Patch for an Issue #919
2014-11-10 13:41:53 +01:00
Miroslav Stampar
06bb957d13
Preventing a run of duplicate issues
2014-11-09 22:07:11 +01:00
Miroslav Stampar
de1cf26fe6
Minor patch
2014-11-09 18:58:25 +01:00
Miroslav Stampar
80af465ce3
Fix for an Issue #911
2014-11-09 18:40:49 +01:00
Miroslav Stampar
9fe6ab749b
Bug fix for occureance of ANSI color codes in multiprocessing hash cracking on Windows OS
2014-11-09 15:08:44 +01:00
Miroslav Stampar
62a73bf30b
Minor fix for automatic removal of temporary files
2014-11-09 14:52:50 +01:00
Miroslav Stampar
d400dc27f2
Patch for an Issue #907
2014-11-08 21:54:34 +01:00
Miroslav Stampar
5e9c73f9c1
Just in case update (for unhandled exceptions happening too soon)
2014-11-08 21:44:46 +01:00
Miroslav Stampar
3b06665c9f
Patch for an Issue #910
2014-11-08 21:22:03 +01:00
Miroslav Stampar
8fdf9ff746
Probable fix for an Issue #908
2014-11-07 15:47:42 +01:00
Miroslav Stampar
d087565051
Fix for Issues #905 and #906
2014-11-06 11:41:10 +01:00
Miroslav Stampar
31f8d6e612
Fix for an Issue #904
2014-11-06 11:19:05 +01:00
Miroslav Stampar
a91fb4149b
Minor update (using lower frequency alphabet for kb.chars)
2014-11-05 10:56:30 +01:00
Miroslav Stampar
a074efe75e
Minor improvement of error-based SQLi when trimmed output is detected (trying to reconstruct)
2014-11-05 10:46:11 +01:00
Miroslav Stampar
71c43be53a
Patch for an Issue #901
2014-11-05 10:03:19 +01:00
Miroslav Stampar
78cc3853b6
Fix for an Issue #902
2014-11-05 09:56:50 +01:00
Miroslav Stampar
97cc679f9c
Fix for an Issue #900
2014-11-04 15:15:58 +01:00
Miroslav Stampar
4d5b48b2ae
Patch for an Issue #896
2014-11-04 00:34:35 +01:00
Miroslav Stampar
6f45596f28
Minor style update
2014-11-03 23:48:44 +01:00
Miroslav Stampar
954bd54689
Fix for an Issue #895
2014-11-03 08:31:50 +01:00
Miroslav Stampar
05b446b95d
Patch for an Issue #893
2014-11-02 23:38:52 +01:00
Miroslav Stampar
9652e41226
Path for an Issue #891
2014-11-02 23:32:19 +01:00
Miroslav Stampar
1ef2c4006d
Patch for an Issue #892
2014-11-02 11:01:46 +01:00
Miroslav Stampar
a4d058d70c
More anonymization of unhanded exception data
2014-11-02 10:55:38 +01:00
Miroslav Stampar
baf9ada28d
Fix for an Issue #889
2014-11-01 17:13:33 +01:00
Miroslav Stampar
4e0e64d06b
Bug fix for DNS Exfiltration in PgSQL case ('invalid URI')
2014-10-31 20:28:37 +01:00
Miroslav Stampar
49d3860b1f
Minor fix
2014-10-31 20:22:15 +01:00
Miroslav Stampar
ab269f315f
Fix for an Issue #886
2014-10-31 18:58:30 +01:00
Miroslav Stampar
65c3dfd651
Bug fix (proper path joining)
2014-10-31 18:40:11 +01:00
Miroslav Stampar
c33e493e0d
Fix for an Issue #885
2014-10-31 17:06:09 +01:00
Miroslav Stampar
4de4f5c1ba
Minor style fix
2014-10-31 16:59:31 +01:00
Miroslav Stampar
38978c3e54
Fix for an Issue #884
2014-10-31 16:45:26 +01:00
Miroslav Stampar
0feb379b47
Fix for an Issue #887
2014-10-31 16:39:29 +01:00
Miroslav Stampar
5b0d74146e
Fix for an Issue #883
2014-10-31 01:01:35 +01:00
Miroslav Stampar
b7aeb670e1
Implementation of a new MySQL error-based payload (found at RDot)
2014-10-29 10:14:01 +01:00
Miroslav Stampar
8ea22c5124
Fix for an Issue #878
2014-10-28 15:34:53 +01:00
Miroslav Stampar
67279a1136
Minor update
2014-10-28 15:30:05 +01:00
Miroslav Stampar
455ea9922c
Minor update
2014-10-28 15:26:28 +01:00
Miroslav Stampar
9af6d497dc
Minor bug fix
2014-10-28 15:22:54 +01:00
Miroslav Stampar
258a700b2e
More anonymization of unhandled exception messages
2014-10-28 15:14:41 +01:00
Miroslav Stampar
df73be32f1
Fix for an Issue #876
2014-10-28 14:41:21 +01:00
Miroslav Stampar
725c3a6a95
Minor update
2014-10-28 14:08:06 +01:00
Miroslav Stampar
3b3b8d4ef2
Potential bug fix (escaping formatted regular expressions)
2014-10-28 14:02:55 +01:00
Miroslav Stampar
268e774087
Minor refactoring
2014-10-28 13:44:55 +01:00
Miroslav Stampar
f89e94fb8c
Minor refactoring
2014-10-28 13:42:13 +01:00
Miroslav Stampar
e08c8f272a
Fix for an Issue #875
2014-10-28 13:10:07 +01:00
Miroslav Stampar
19aed90ae5
Implementation for an Issue #874
2014-10-27 00:37:46 +01:00
Miroslav Stampar
6448d3caf4
Implementing support for csrfcookie (Issue #2 )
2014-10-24 09:37:51 +02:00
Miroslav Stampar
5e31229d48
Minor cosmetic update
2014-10-23 15:18:22 +02:00
Miroslav Stampar
abbd352392
Support for X-CSRF-TOKEN header (Issue #2 )
2014-10-23 14:33:22 +02:00
Miroslav Stampar
95f2e61ca1
Minor fix related to the Issue #2
2014-10-23 14:23:01 +02:00
Miroslav Stampar
01f4b76817
Minor update for the Issue #2
2014-10-23 14:03:44 +02:00
Miroslav Stampar
7143e61619
Minor update
2014-10-23 14:00:53 +02:00
Miroslav Stampar
32bcca0aae
Basic options check for Issue #2
2014-10-23 11:54:29 +02:00
Miroslav Stampar
7fc9e82d28
Minor style update
2014-10-23 11:44:38 +02:00
Miroslav Stampar
780dbd1c64
Update for an Issue #2
2014-10-23 11:42:30 +02:00
Miroslav Stampar
a52c8811e6
Minor style update
2014-10-23 11:25:44 +02:00
Miroslav Stampar
fc1b05bec9
Implementation for an Issue #2
2014-10-23 11:23:53 +02:00
Miroslav Stampar
8dcad46805
Update basic.py
2014-10-22 23:16:46 +02:00
Miroslav Stampar
73a3db67eb
Fix for an Issue #862
2014-10-22 14:54:49 +02:00
Miroslav Stampar
60f2764c3d
Minor style update
2014-10-22 13:53:18 +02:00
Miroslav Stampar
34aed7cde0
Bug fix (now it's possible to use multiple parsed requests without mixing associated headers)
2014-10-22 13:49:29 +02:00
Miroslav Stampar
2f18df345e
Minor patch
2014-10-22 13:41:36 +02:00
Miroslav Stampar
268095495e
Minor patch
2014-10-22 13:32:49 +02:00
Miroslav Stampar
e239fefe67
Minor patch for JSON requests
2014-10-22 10:38:49 +02:00
Miroslav Stampar
a2f578dbf4
Patch to also include JSON array elements into automatic recognition
2014-10-22 10:28:10 +02:00
Miroslav Stampar
3ebc5faa34
Falling back to partial UNION if large dump connects out
2014-10-21 09:23:34 +02:00
Miroslav Stampar
1b18035eb3
Correcting language code
2014-10-14 13:00:51 +02:00
Miroslav Stampar
50e7cae915
Minor update
2014-10-14 09:32:01 +02:00
Miroslav Stampar
19b0bc5a92
Adding a Croatian translation of README.md
2014-10-14 09:31:03 +02:00
Miroslav Stampar
db30b37f8a
Removing translations from already translated pages (to ease the inclusion of other languages)
2014-10-14 09:00:26 +02:00
Miroslav Stampar
006d9d1859
Bug fix for a problem reported by a user via ML (--os-shell)
2014-10-13 12:00:34 +02:00
Miroslav Stampar
fb65caabd2
Unhidding switch --ignore-401
2014-10-13 09:19:25 +02:00
Miroslav Stampar
6db4b29fd3
Adding contributed Greek and Chinese translations
2014-10-13 09:02:33 +02:00
Miroslav Stampar
be213bc657
Bug fix for crashes caused by '--search --exclude-sysdbs --current-db'
2014-10-12 22:41:53 +02:00
Miroslav Stampar
4e3a4eb0ff
Added a prompt for choosing a number of threads when in crawling mode
2014-10-10 12:09:08 +02:00
Miroslav Stampar
2aadfc0fd3
Fix for an Issue #851
2014-10-10 10:38:17 +02:00
Miroslav Stampar
d4610890ca
Minor patch (flushing log file output at the end of program run)
2014-10-10 10:07:17 +02:00
Miroslav Stampar
7811a958ae
Another minor patch for Issue #846
2014-10-09 15:42:44 +02:00
Miroslav Stampar
f94ac8c69d
Second patch related to the Issue #846
2014-10-09 15:21:26 +02:00
Miroslav Stampar
c823c58d47
One patch related to the Issue #846
2014-10-09 14:39:54 +02:00
Miroslav Stampar
35ed668a85
Minor improvement of the randomcase tamper script
2014-10-07 13:09:37 +02:00
Miroslav Stampar
70215a95a1
Patch for an Issue #847
2014-10-07 13:02:47 +02:00
Miroslav Stampar
c6a8feea8a
Fix for an Issue #831
2014-10-07 12:00:11 +02:00
Miroslav Stampar
2ab4558859
Potential fix for an Issue #846
2014-10-07 11:49:53 +02:00
Miroslav Stampar
ddfec1c668
Initial patch for an Issue #846
2014-10-07 11:34:47 +02:00
Miroslav Stampar
2f37fb295b
Minor fix regarding Issue #845
2014-10-07 10:31:17 +02:00
Miroslav Stampar
9d25389ef0
Minor fix regarding Issue #845
2014-10-07 10:20:40 +02:00
Miroslav Stampar
2de12ef4a2
Potential fix for an Issue #843
2014-10-05 00:20:42 +02:00
Miroslav Stampar
45122582cf
Year update in COPYING
2014-10-01 14:25:54 +02:00
Miroslav Stampar
fdef53aa67
Minor update of unhandled exception message
2014-10-01 14:23:45 +02:00
Miroslav Stampar
a2b059123a
Minor update of format exception strings
2014-10-01 14:12:30 +02:00
Miroslav Stampar
e81168af0f
Minor adjustment
2014-10-01 13:59:51 +02:00
Miroslav Stampar
f67a38dba9
Minor adjustment
2014-10-01 13:42:10 +02:00
Miroslav Stampar
a9454fbb43
Minor commit related to the last one (bypassing DBMS error trimming problem)
2014-10-01 13:35:20 +02:00
Miroslav Stampar
8c9014c39f
Adding a dummy (auxiliary) XSS check
2014-10-01 13:31:48 +02:00
Miroslav Stampar
4d23744430
Bug fix (there was a problem using --tamper=varnish with --identify-waf because of same named modules)
2014-09-30 09:58:02 +02:00
Miroslav Stampar
ff42720c62
Minor fix
2014-09-29 14:07:59 +02:00
Miroslav Stampar
1e636fb925
Minor patch regarding Issue #840
2014-09-28 13:38:09 +02:00
Miroslav Stampar
767c278a0f
Fix for an Issue #838
2014-09-26 17:00:50 +02:00
Miroslav Stampar
f272517cd2
Dealing with broken pipe (not filling terminal with traceback in that case)
2014-09-22 22:18:08 +02:00
Miroslav Stampar
6945a0a570
Changing @ with (at) in THANKS.md
2014-09-20 14:52:14 +02:00
Miroslav Stampar
46480d777a
Update for an Issue #835
2014-09-20 14:48:36 +02:00
Miroslav Stampar
78965b8145
Merge pull request #835 from mmetince/master
...
Add random X-Forwarded-For to bypass IP Ban.
2014-09-20 14:31:26 +02:00
Miroslav Stampar
00fc842c6f
Update agent.py
2014-09-20 10:20:57 +02:00
Mehmet INCE
d34a57041e
Add random X-Forwarded-For to bypass IP Ban.
2014-09-19 20:59:33 +03:00
Miroslav Stampar
69701ba08c
Minor refactoring
2014-09-17 18:29:01 +02:00
Miroslav Stampar
09064a4a24
Minor just in case patch
2014-09-17 18:25:24 +02:00
Miroslav Stampar
bbc6dd9ac8
Minor fix
2014-09-17 10:28:18 +02:00
Miroslav Stampar
6888d2fc34
Minor cosmetic update
2014-09-16 16:32:54 +02:00
Miroslav Stampar
8a92dd3aaa
Minor cosmetic patch
2014-09-16 16:28:38 +02:00
Miroslav Stampar
0e8090381c
Minor cosmetic update
2014-09-16 16:21:29 +02:00
Miroslav Stampar
c5294f2cbb
Minor patch for an Issue #832
2014-09-16 16:18:13 +02:00
Miroslav Stampar
5b0732e9f9
Minor update for Issue #832
2014-09-16 15:17:50 +02:00
Miroslav Stampar
7278af01ee
Implementation for an Issue #832
2014-09-16 14:12:43 +02:00
Miroslav Stampar
57eb19377e
Minor code refactoring
2014-09-16 09:07:31 +02:00
Miroslav Stampar
45f5548113
Minor update regarding shell history file
2014-09-16 08:58:25 +02:00
Miroslav Stampar
ffa7e2f6e9
Minor fix
2014-09-14 22:57:41 +02:00
Miroslav Stampar
637d3cbaf7
Fix for cases when parameter name is urlencoded
2014-09-12 13:29:30 +02:00
Miroslav Stampar
ae8c12c9c3
Fix for an Issue #818
2014-09-09 16:22:13 +02:00
Miroslav Stampar
90869244fd
Minor update
2014-09-09 16:19:38 +02:00
Miroslav Stampar
bfc8ab0e35
Language update
2014-09-08 14:48:31 +02:00
Miroslav Stampar
53d0d5bf8b
Minor update (adding a warning message about potential dropping of requests because of protection mechanisms involved)
2014-09-08 14:33:13 +02:00
Miroslav Stampar
055b759145
Minor update
2014-09-03 23:13:57 +02:00
Miroslav Stampar
b1467f4c1f
Minor update
2014-09-03 23:09:10 +02:00
Miroslav Stampar
bbf0be1f8d
Bug fix (Issue #813 )
2014-09-03 22:09:12 +02:00
Miroslav Stampar
112a0cb1ae
Patch for output directory (using unicode for international support)
2014-09-03 21:49:30 +02:00
Miroslav Stampar
af21fc513d
Bug fix for HSQLDB (some queries were runnable on MySQL)
2014-09-03 21:39:38 +02:00
Miroslav Stampar
1478c206f1
Trivial update
2014-09-03 21:27:02 +02:00
Miroslav Stampar
7e40890f32
Patch for an Issue #815
2014-09-01 16:16:12 +02:00
Miroslav Stampar
25c6fca20e
Minor fix
2014-09-01 15:48:00 +02:00
Miroslav Stampar
d5d01e91ad
Warning message
2014-08-30 22:15:14 +02:00
Miroslav Stampar
20ff402103
Minor patch
2014-08-30 22:04:55 +02:00
Miroslav Stampar
dc2ee8bfa0
Minor update
2014-08-30 21:53:09 +02:00
Miroslav Stampar
177fc0376d
Minor fix for HSQLDB
2014-08-30 21:37:38 +02:00
Miroslav Stampar
1a9a331422
Bug fix (proper extending of tests when dbms is known)
2014-08-30 21:34:23 +02:00
Miroslav Stampar
e501b2a80b
Minor patch
2014-08-30 20:58:59 +02:00
Miroslav Stampar
03c8e7b7a2
Patch for an Issue #810
2014-08-30 17:13:02 +02:00
Miroslav Stampar
77cb35dcf6
Fix for an Issue #804
2014-08-28 14:26:55 +02:00
Miroslav Stampar
9476359255
Bug fix
2014-08-28 12:50:39 +02:00
Miroslav Stampar
fa1cfa21e6
Improvement to BlueCoat's tamper script
2014-08-28 12:34:15 +02:00
Miroslav Stampar
13bf338f86
Implementation for an Issue #806
2014-08-28 11:58:22 +02:00
Miroslav Stampar
2408f9c1e1
Merge pull request #803 from shipcod3/master
...
Create sucuri.py
2014-08-28 09:36:51 +02:00
Jay Turla
911f27116a
Update sucuri.py
2014-08-28 09:23:44 +08:00
Jay Turla
539c2e2b50
Create sucuri.py
...
adding Sucuri WebSite Firewall detection
2014-08-28 08:53:21 +08:00
Miroslav Stampar
834f8e18c8
Minor patch for an Issue #802
2014-08-28 00:45:57 +02:00
Miroslav Stampar
b77d8d617b
Minor patch for an Issue #800
2014-08-28 00:31:49 +02:00
Miroslav Stampar
7595f2b73e
Minor fix
2014-08-28 00:13:27 +02:00
Miroslav Stampar
fce671c899
Patch for an Issue #801
2014-08-28 00:00:16 +02:00
Miroslav Stampar
fd36250026
Proper fix for an Issue #757
2014-08-26 23:36:04 +02:00
Miroslav Stampar
2a268199d4
Patch for an Issue #798
2014-08-26 23:11:44 +02:00
Miroslav Stampar
e68326c0fe
expandAsteriskForColumns changes value of conf.db and conf.tbl potentially causing problems in further work
2014-08-26 22:57:08 +02:00
Miroslav Stampar
decd092b2a
Minor patch
2014-08-26 22:40:50 +02:00
Miroslav Stampar
2be0ebd883
Minor fix (e.g. Oracle identifier names can contain character $)
2014-08-26 22:40:15 +02:00
Miroslav Stampar
dcaad75a1e
Fix for an Issue #794
2014-08-22 15:08:05 +02:00
Miroslav Stampar
d74b803306
Minor patch
2014-08-22 14:45:23 +02:00
Miroslav Stampar
e0a8b89069
Minor patch when trailing space is used with comma to split option items (e.g. '-C id, name')
2014-08-22 14:19:53 +02:00
Miroslav Stampar
e3a0f25db0
Patch for an Issue #795
2014-08-22 14:11:23 +02:00
Miroslav Stampar
2ce3ccac46
Patch for an Issue #797 (switching to greedy because of performance; it shouldn't be a problem because it was a single line replacement in the first place)
2014-08-22 13:06:53 +02:00
Miroslav Stampar
77513e1de9
Minor style update
2014-08-21 01:19:10 +02:00
Miroslav Stampar
c5b71cff10
Some filtering
2014-08-21 01:12:44 +02:00
Miroslav Stampar
3cfdb5ff0f
Removing / from auto directories (it doesn't make sense to auto-test for uploading to /)
2014-08-21 00:43:37 +02:00
Miroslav Stampar
1069399668
Minor style update
2014-08-21 00:32:15 +02:00
Miroslav Stampar
acb3b1d1fe
Bug fix for common table/column existence check
2014-08-21 00:12:19 +02:00
Miroslav Stampar
074b57804e
Minor style update
2014-08-21 00:03:46 +02:00
Miroslav Stampar
58d93ffb2b
Fix for falling back to partial union (excluding scalar queries)
2014-08-20 23:53:15 +02:00
Miroslav Stampar
90882f081d
Language update
2014-08-20 23:47:57 +02:00
Miroslav Stampar
0296081692
Minor refactoring
2014-08-20 23:42:40 +02:00
Miroslav Stampar
49e8083b40
Bug fix for international letters (range in 160-255 is also printable)
2014-08-20 23:28:45 +02:00
Miroslav Stampar
f51ea20bbd
Minor style update
2014-08-20 22:50:00 +02:00
Miroslav Stampar
5d10bae31f
Removing trailing blank lines
2014-08-20 21:07:19 +02:00
Miroslav Stampar
e0216771ed
Minor update
2014-08-20 15:23:07 +02:00
Miroslav Stampar
c97782cfed
Minor update of banner
2014-08-20 15:10:21 +02:00
Miroslav Stampar
ff8bfff87a
Bug fix (FreeBSD != Linux)
2014-08-20 14:45:58 +02:00
Miroslav Stampar
07f881e711
Minor fix
2014-08-20 14:02:04 +02:00
Miroslav Stampar
b4fbb9cafe
Minor upgrade
2014-08-20 13:52:48 +02:00
Miroslav Stampar
7828f61642
Minor style update
2014-08-20 13:35:41 +02:00
Miroslav Stampar
dfa426fbb5
Minor style update
2014-08-20 13:32:32 +02:00
Miroslav Stampar
6795b51c7e
Another minor update
2014-08-20 01:59:30 +02:00
Miroslav Stampar
d08c1b7c04
Minor update
2014-08-20 01:45:42 +02:00
Miroslav Stampar
6caccc3d93
Bug fix for ultra-slow processing of binary data
2014-08-20 01:38:01 +02:00
Miroslav Stampar
ebc964267f
Better reporting on filtered-chars cases
2014-08-20 01:11:26 +02:00
Miroslav Stampar
c12e51173a
Minor style update
2014-08-20 00:28:33 +02:00
Miroslav Stampar
77ba63b060
Minor language update
2014-08-19 23:56:04 +02:00
Miroslav Stampar
4dd6887ea4
Fix for an Issue #793
2014-08-19 22:48:18 +02:00
Miroslav Stampar
5a05271097
Minor fix
2014-08-19 22:34:07 +02:00
Miroslav Stampar
b0465a6a76
Adding a revision scheme for nongit checkouts
2014-08-19 22:32:16 +02:00
Miroslav Stampar
cd92de1702
Adding colorful banner
2014-08-19 22:19:22 +02:00
Miroslav Stampar
7d578d395f
Minor update for Apache on Windows
2014-08-16 16:01:18 +02:00
Miroslav Stampar
a8b4b96cd9
Extending list for brute forcing doc root
2014-08-16 15:16:03 +02:00
Miroslav Stampar
30fb8e8a50
Patch regarding Issue #774 (SELECT is redundant in case of LOAD_FILE)
2014-08-16 14:23:07 +02:00
Miroslav Stampar
0fb576724e
Implementation for cases when there are multiple copies/variations of the same result(s) in response for partial UNION SQLi
2014-08-13 22:50:42 +02:00
Miroslav Stampar
0809a61fc3
Bug fix (whole page output as a result of partial union runs)
2014-08-13 15:18:11 +02:00
Miroslav Stampar
0a74ae736f
Probable fix for an Issue #788
2014-08-13 14:01:57 +02:00
Miroslav Stampar
5436635acb
Minor update
2014-08-13 13:32:22 +02:00
Miroslav Stampar
f7f47c71a1
Fix for an Issue #789
2014-08-13 13:19:03 +02:00
Miroslav Stampar
658110e644
Minor fix
2014-08-11 12:46:37 +02:00
Bernardo Damele A. G.
f110bfe28a
Merge pull request #779 from hydhyd/patch-1
...
Update settings.py
2014-08-06 10:45:42 +01:00
hydhyd
e7ffe92d8c
Update settings.py
...
Modified BRUTE_DOC_PREFIXES to include "/srv/www" used by default in OpenSUSE.
2014-08-06 12:59:18 +04:00
Bernardo Damele A. G.
2da94ba82d
minor doc update
2014-08-04 16:46:01 +01:00
Miroslav Stampar
8599005115
Implementation for an Issue #771
2014-08-01 14:19:32 +02:00
Miroslav Stampar
208d51e0e9
Revert of last trigger happy commit
2014-08-01 13:57:43 +02:00
Miroslav Stampar
d300f99b0b
Removing a redundant code (similar check is being done upper in code)
2014-08-01 13:57:07 +02:00
Miroslav Stampar
8bc6154f06
Removing a redundant code (similar check is being done upper in code)
2014-08-01 13:53:22 +02:00
Miroslav Stampar
b31e141012
Fix for an Issue #772
2014-07-29 14:37:48 +02:00
Miroslav Stampar
20d75cc52e
Patch for an Issue #767
2014-07-29 13:32:26 +02:00
Miroslav Stampar
6c4c82758d
Fix for an Issue #768
2014-07-29 13:26:58 +02:00
Miroslav Stampar
9fff88d6e4
Minor update
2014-07-19 23:23:55 +02:00
Miroslav Stampar
3cfa63646b
Minor bug fix
2014-07-19 23:17:23 +02:00
Miroslav Stampar
0eb5fb1e5a
Update for an Issue #757
2014-07-19 23:02:14 +02:00
Bernardo Damele
a09e590fe8
updated regression tests
2014-07-17 17:13:09 +01:00
Miroslav Stampar
cd1c100cc0
Another patch for an Issue #757
2014-07-14 21:10:45 +02:00
Miroslav Stampar
e66a81ab4e
Fix for an Issue #757
2014-07-11 16:24:57 +02:00
Miroslav Stampar
305ec45fc6
Update for an Issue #760
2014-07-10 08:52:32 +02:00
Miroslav Stampar
32af0b17b0
Update for an Issue #760
2014-07-10 08:49:20 +02:00
Miroslav Stampar
33b6d189cd
Bug fix for some cases (in cases of working where=ORIGINAL, workflow switched to where=NEGATIVE because of false assumptions that it would be better than ORIGINAL; this kind of behaviour caused reported problems)
2014-07-07 22:22:56 +02:00
Miroslav Stampar
f75df93c0e
Update related to the Issue #756
2014-07-07 21:11:40 +02:00
Miroslav Stampar
65795c0b4f
Merge pull request #756 from za/master
...
Translate GitHub README.md to Indonesian
2014-07-07 21:07:59 +02:00
Zaki Akhmad
833a51411c
id-ID: translate the README to Indonesian
2014-07-07 13:42:17 +07:00
Zaki Akhmad
fada2dc5c6
id-ID: initiate Indonesian translations README
2014-07-07 13:21:07 +07:00
Miroslav Stampar
79a66ef22c
Minor patch
2014-07-06 09:09:44 +02:00
Miroslav Stampar
a8580d67ff
Merge pull request #749 from igoremuniz/master
...
update copyright for 2014
2014-07-03 09:03:22 +02:00
Igor Elias
8105275d9d
...
2014-07-02 21:23:25 -03:00
Igor Elias
e6916bdbc6
updated copyright
2014-07-02 21:16:35 -03:00
Miroslav Stampar
b5838ae7a4
Adding missing module (Issue #674 and Issue #747 )
2014-07-03 00:29:20 +02:00
Miroslav Stampar
9d571c7800
Minor language update
2014-07-02 22:31:18 +02:00
Miroslav Stampar
e6d0d5a1c7
Implementation for an Issue #674
2014-07-02 22:27:51 +02:00
Miroslav Stampar
1eecabaea8
Patch for an Issue #746
2014-07-02 10:11:31 +02:00
Bernardo Damele
4e909a2a05
code cleanup
2014-07-01 00:58:49 +01:00
Bernardo Damele
b38bd1e7fd
code cleanup - issue #742
2014-07-01 00:35:02 +01:00
Bernardo Damele
018748f52e
increase the timeout for the Metasploit session initialization to 5 minutes, better on slow speed connections
2014-07-01 00:34:09 +01:00
Bernardo Damele
5c64a31a9c
works now.. can upload arbitrary files via powershell now, closes #742
2014-07-01 00:26:59 +01:00
Bernardo Damele
3e431ec202
working on allowing large files to be uploaded via powershell - issue #742
2014-06-30 23:53:04 +01:00
Miroslav Stampar
e34be17255
Merge pull request #744 from cbrunnkvist/master
...
Random means no User-Agent
2014-06-30 22:33:34 +02:00
Bernardo Damele
1218e694ef
more on issue #742
2014-06-30 20:43:48 +01:00
Bernardo Damele
8ce98ae22c
more on issue #742
2014-06-30 20:43:02 +01:00
Bernardo Damele
0c1b3f2dbc
more on issue #742
2014-06-30 20:39:21 +01:00
Bernardo Damele
ce67156d80
trying some more encoding as the file wasnt exactly the same - issue #742
2014-06-30 20:26:05 +01:00
Bernardo Damele
3ec37b14a6
trying some more encoding as the file wasnt exactly the same - issue #742
2014-06-30 20:23:57 +01:00
Bernardo Damele
9c583bc96e
trying some more encoding as the file wasnt exactly the same - issue #742
2014-06-30 20:23:01 +01:00
Bernardo Damele
5c4c4c6abe
minor cleanup, prefer powershell to the other two techniques to upload files - issue #742
2014-06-30 19:11:01 +01:00
Bernardo Damele
fcc50193b3
working on #742 - working on it
2014-06-30 18:50:33 +01:00
Bernardo Damele
4be0b366eb
working on #742 - working on it
2014-06-30 18:38:18 +01:00
Conny Brunnkvist
f0e23c9441
Use the selected random User-Agent
2014-07-01 00:27:14 +07:00
Bernardo Damele
6999c3413c
working on #742 - working on it
2014-06-30 18:26:40 +01:00
Bernardo Damele
aa076013a7
working on #742 - minor fixes
2014-06-30 18:18:14 +01:00
Bernardo Damele
563c73c4c7
working on #742 - code cleanup
2014-06-30 18:09:11 +01:00
Bernardo Damele
94c09019fd
working on #742 - missing import
2014-06-30 18:07:45 +01:00
Bernardo Damele
cd260a7470
working on #742 - powershell support for file write on MSSQL
2014-06-30 18:06:19 +01:00
Bernardo Damele
e2aed41c6f
minor fixed
2014-06-30 17:30:20 +01:00
Miroslav Stampar
c2f14e57e7
Patch for an Issue #740
2014-06-29 00:27:23 +02:00
Miroslav Stampar
686fe4d0e9
Another patch for DNS exfiltration and boolean checks
2014-06-27 14:22:00 +02:00
Miroslav Stampar
8e660e6911
Minor fix
2014-06-27 14:14:29 +02:00
Miroslav Stampar
2f8d17bcb7
Appendix to last commit
2014-06-27 13:45:40 +02:00
Miroslav Stampar
75279ea75a
Fix for DNS exfiltration of boolean checks
2014-06-27 13:07:34 +02:00
Miroslav Stampar
ac43051df2
Patch for an Issue #553
2014-06-23 21:24:45 +02:00
Miroslav Stampar
5b5a765f96
Patch for an Issue #734
2014-06-23 12:24:08 +02:00
Miroslav Stampar
11dee4c8cd
Patch for an Issue #731
2014-06-22 00:19:10 +02:00
Miroslav Stampar
a47072eced
Patch for an Issue #732
2014-06-22 00:09:08 +02:00
Miroslav Stampar
2a88436417
Patch for an Issue #724
2014-06-16 09:51:24 +02:00
Miroslav Stampar
f558b800ac
Patch for an Issue #719
2014-06-12 09:08:55 +02:00
Miroslav Stampar
2beeb178fb
Minor patch
2014-06-12 08:56:50 +02:00
Miroslav Stampar
295b2f8603
Merge pull request #714 from securitygeneration/patch-1
...
Modified regex to be case insensitive
2014-06-10 21:59:14 +02:00
Miroslav Stampar
c50560c3a6
Patch for an Issue #716
2014-06-10 21:57:54 +02:00
Miroslav Stampar
5e9334ab79
Implementation for an Issue #715
2014-06-08 23:55:15 +02:00
securitygeneration
5659eeec10
Modified regex to be case insensitive
...
Changed the regular expression to be case insensitive so that it works with the randomcase.py tamper script.
2014-06-08 19:14:38 +01:00
Miroslav Stampar
dac386735a
Patch for an Issue #713
2014-06-08 12:34:12 +02:00
Miroslav Stampar
54be398e83
Patch for an Issue #711
2014-06-04 16:35:07 +02:00
Miroslav Stampar
27ebc02535
Minor fix (user reported problem via email)
2014-05-29 09:33:14 +02:00
Miroslav Stampar
0f10cdfa4c
Minor update
2014-05-29 09:24:09 +02:00
Miroslav Stampar
9e02816cbd
Raising number of used md5 digits in hashdb key value because of birthday paradox (Python can handle it - automatically expanding to long if required; SQLite can handle it - it will use 6 bytes per INTEGERs instead of 4)
2014-05-29 09:21:48 +02:00
Miroslav Stampar
680ab10ca6
Patch for an Issue #703
2014-05-27 21:41:07 +02:00
Miroslav Stampar
8b341e86fa
Merge pull request #701 from mwulftange/derived-table-boundaries
...
Add boundary checks for derived tables in FROM clause
2014-05-26 13:44:25 +02:00
Markus Wulftange
cf4e0c755b
Add boundary checks for derived tables in FROM clause
2014-05-24 17:25:11 +02:00
Miroslav Stampar
2d5461d250
Minor fix (related to the unknown encoding reported by ML)
2014-05-22 09:03:14 +02:00
Miroslav Stampar
65c4ea1562
Minor update
2014-05-20 22:30:53 +02:00
Miroslav Stampar
24954776a5
Patch for an Issue #697
2014-05-20 22:00:26 +02:00
Miroslav Stampar
babe49f086
Minor update (added new warning message)
2014-05-20 17:14:40 +02:00
Miroslav Stampar
401f896175
Patch related to the Issue #696
2014-05-20 13:44:10 +02:00
Miroslav Stampar
67115ed558
Minor fix (for a bug reported via ML)
2014-05-17 15:00:09 +02:00
Miroslav Stampar
c181e909b5
Minor fix
2014-05-16 23:47:00 +02:00
Miroslav Stampar
c51e219cc1
Fix for an Issue #691
2014-05-15 19:39:18 +02:00
Miroslav Stampar
fc3c321b01
Minor update
2014-05-15 19:08:41 +02:00
Miroslav Stampar
0f581ccb6c
Minor fix
2014-05-13 15:36:28 +02:00
Miroslav Stampar
4e8b41b869
Patch for an Issue #688
2014-05-13 00:50:36 +02:00
Miroslav Stampar
3a2916724c
Minor style update
2014-05-11 17:12:15 +02:00
Miroslav Stampar
a72d73804e
Revert of 9255174890 (bug was introduced with it)
2014-05-10 01:31:44 +02:00
Miroslav Stampar
93bf8e2a13
Bug fix
2014-05-10 01:11:19 +02:00
Miroslav Stampar
8f0807d7f9
Another fix related to the last commit
2014-05-09 22:55:16 +02:00
Miroslav Stampar
5eae002084
Minor fix
2014-05-09 22:45:43 +02:00
Miroslav Stampar
9255174890
Minor fix
2014-05-09 22:39:56 +02:00
Miroslav Stampar
5c4e4d18ee
Update for an Issue #686
2014-05-07 09:35:45 +02:00
Miroslav Stampar
5755290f98
Update for an Issue #686
2014-05-07 09:29:01 +02:00
Miroslav Stampar
6a3d7f28f1
Update for an Issue #686
2014-05-07 09:21:00 +02:00
Miroslav Stampar
bc4369be06
Fix for an Issue #687
2014-05-07 09:16:17 +02:00
Bernardo Damele A. G.
73f79f5481
Merge pull request #686 from viniciusmarangoni/master
...
Update README-por.md
2014-05-06 07:55:01 +00:00
Vinícius Henrique Marangoni
99f852e770
Update README-por.md
2014-05-06 00:43:34 -03:00
Miroslav Stampar
ae5325ed31
Minor update regarding Issue #684
2014-05-05 22:17:01 +02:00
Miroslav Stampar
2c586e8ef6
Merge pull request #684 from viniciusmarangoni/master
...
Create README-Portugues.md in doc folder
2014-05-05 22:14:35 +02:00
Vinícius Henrique Marangoni
9ea9c19b55
Create README-Portugues.md
2014-05-05 02:35:32 -03:00
Miroslav Stampar
e7bc57b00b
Fix for an Issue #683
2014-05-04 20:44:11 +02:00
Miroslav Stampar
2a55f75f86
Using a more generic XML recognition regex
2014-04-30 21:25:45 +02:00
Miroslav Stampar
2e96e3c924
Adding a hidden switch --ignore-401
2014-04-29 23:26:45 +02:00
Miroslav Stampar
bd16bb7a6a
Adding an appropriate warning message
2014-04-27 22:48:28 +02:00
Miroslav Stampar
eb8e31c23f
Adding a failsafe output directory
2014-04-27 22:40:41 +02:00
Miroslav Stampar
b54651b5a2
Minor patch (while saving configuration file)
2014-04-25 09:32:57 +02:00
Miroslav Stampar
ae8b1fe89c
Implementation for an Issue #678
2014-04-25 09:17:10 +02:00
Miroslav Stampar
efa3c3e451
Minor improvement of between tamper script
2014-04-22 11:04:28 +02:00
Miroslav Stampar
6fd3c27f70
Update for an Issue #672
2014-04-22 08:48:12 +02:00
Miroslav Stampar
e0fb21c26a
Patch for an Issue #673
2014-04-21 21:57:30 +02:00
Miroslav Stampar
f29769b7d0
Minor patch
2014-04-16 09:06:17 +02:00
Miroslav Stampar
ef5ce7e66c
Fix for an Issue #670
2014-04-12 17:22:47 +02:00
Miroslav Stampar
fd884ec67b
Adding another comment
2014-04-12 17:22:47 +02:00
Miroslav Stampar
b5cca742e4
Adding a comment
2014-04-12 17:22:47 +02:00
Bernardo Damele A. G.
f07bdcfda1
Update README.md
...
markdown syntax fix
2014-04-11 14:15:17 +00:00
Miroslav Stampar
7f371c499d
Commit related to the last one
2014-04-10 21:29:59 +02:00
Miroslav Stampar
096ce7881e
Minor beauty patch
2014-04-10 21:18:24 +02:00
Miroslav Stampar
0d1690de61
Minor fix
2014-04-10 21:18:24 +02:00
Miroslav Stampar
1e8349eeaa
Minor fix
2014-04-10 21:18:24 +02:00
Bernardo Damele
78ab525966
minor fix to Oracle payloads
2014-04-09 12:31:52 +00:00
Bernardo Damele
42bde5328d
minor fix
2014-04-09 12:29:52 +00:00
Bernardo Damele
a5aa1c2f94
some more common output for Oracle banner
2014-04-09 12:20:52 +00:00
Bernardo Damele
7f5ea24590
added a few common outputs for --predict-output
2014-04-09 12:14:33 +00:00
Bernardo Damele
9b0662d1a9
added new Oracle time-based payloads
2014-04-09 12:14:16 +00:00
Miroslav Stampar
2d3a74a0fe
Patch for an Issue #667
2014-04-07 21:01:40 +02:00
Miroslav Stampar
cb0044b2c4
Minor beauty patch
2014-04-07 20:28:17 +02:00
Miroslav Stampar
fdad787681
Graceful abort in case of an invalid option in configuration file
2014-04-07 20:22:51 +02:00
Miroslav Stampar
e3ccf45503
Graceful abort in case of an invalid configuration file
2014-04-07 20:17:47 +02:00
Miroslav Stampar
bcf754fb17
Consistency patch (to be the same as in help listing)
2014-04-07 20:10:21 +02:00
Miroslav Stampar
b74de19213
Trivial style update
2014-04-07 20:06:03 +02:00
Miroslav Stampar
75f447ccf8
Renaming lib/core/purge to lib/utils/purge
2014-04-07 20:04:07 +02:00
Miroslav Stampar
9c7fbd1a90
Minor refactoring
2014-04-06 18:19:54 +02:00
Miroslav Stampar
3beb1ae2a1
Trivial fix (backslashes should be escaped)
2014-04-06 18:15:06 +02:00
Miroslav Stampar
4f4c50c4d5
Minor language update
2014-04-06 18:12:59 +02:00
Miroslav Stampar
bf18b025d6
Minor removal of redundant code
2014-04-06 18:09:54 +02:00
Miroslav Stampar
e931344617
More elegant implementation for --random-agent
2014-04-06 18:05:43 +02:00
Miroslav Stampar
9456dc68e7
Minor patch
2014-04-06 17:24:27 +02:00
Miroslav Stampar
1c92d8d51f
More generic implementation for --proxy-file (accepting public lists format)
2014-04-06 17:23:13 +02:00
Miroslav Stampar
36a590e085
Minor language fix
2014-04-06 17:13:23 +02:00
Miroslav Stampar
bbf08a825e
Minor language fix
2014-04-06 17:12:43 +02:00
Miroslav Stampar
cf250a0381
Minor patch (it would go boom if special character was inside the --param-del)
2014-04-06 17:02:32 +02:00
Miroslav Stampar
053b0fd0e9
Renaming conf.oDir to conf.outputDir
2014-04-06 16:54:46 +02:00
Miroslav Stampar
7cc4159316
Renaming conf.cDel to conf.cookieDel
2014-04-06 16:50:58 +02:00
Miroslav Stampar
0ae8ac707e
Renaming conf.pDel to conf.paramDel
2014-04-06 16:48:46 +02:00
Miroslav Stampar
95e7ca02f0
Minor bug fix (-d was not recognized as one of mandatory in case of config file)
2014-04-06 16:45:25 +02:00
Miroslav Stampar
1b3a98b8ef
Trivial update (for consistency sake)
2014-04-06 13:42:15 +02:00
Miroslav Stampar
492a410bcc
Minor fix
2014-04-04 16:14:53 +02:00
Miroslav Stampar
15f92c4197
Bug fix (port was not being used properly with Burp exported history)
2014-04-03 09:46:37 +02:00
Miroslav Stampar
1632bec10b
Another fix related to the last commit
2014-04-03 09:05:12 +02:00
Miroslav Stampar
e7e8a3965a
Minor fix
2014-04-03 09:00:14 +02:00
Miroslav Stampar
80d4426dbd
Patch related to the Issue #661
2014-04-02 22:34:37 +02:00
Miroslav Stampar
d8bacc904e
Minor language update
2014-04-01 16:38:50 +02:00
Miroslav Stampar
3e024ac8e6
Minor update (consistency patch)
2014-03-30 16:51:31 +02:00
Miroslav Stampar
76b9fad24a
Fix for an Issue #656
2014-03-30 16:21:18 +02:00
Miroslav Stampar
b2cc8f00ef
Bug fix (ORACLE_OLD on Windows - resulted in multiple entry per line output due to no locking used)
2014-03-28 00:41:22 +01:00
Miroslav Stampar
e8c1c90f2e
Whitespace was being double encoded in case of spaceplus (' '->%2B)
2014-03-25 22:02:14 +01:00
Miroslav Stampar
3710a7051b
Fix for an Issue #653
2014-03-25 21:26:22 +01:00
Miroslav Stampar
930c3e3c5a
Minor update (added check for --limit and --risk)
2014-03-25 09:28:12 +01:00
Miroslav Stampar
f6e1d9e026
Fix for an Issue #650
2014-03-24 10:46:23 +01:00
Miroslav Stampar
106102bd3c
Fix for an Issue #648
2014-03-21 20:28:29 +01:00
Bernardo Damele
276dab781b
forgot commend, mandatory
2014-03-21 11:50:12 +00:00
Bernardo Damele
9f838c3d5b
typo fix
2014-03-21 11:37:34 +00:00
Bernardo Damele
bc5c0ee4ae
reverted previous commit, it must be OUTFILEP: LINES TERMINATED BY does not work with DUMPFILE
2014-03-21 11:36:46 +00:00
Bernardo Damele
8091a88d3e
minor code cleanup and bug fix
2014-03-21 11:35:30 +00:00
Bernardo Damele
c211255773
replaced outfile with dumpfile so works even if the original statement outputs blob
2014-03-21 11:01:57 +00:00
Miroslav Stampar
39ab3b9149
Minor fix for meta refresh
2014-03-20 13:13:47 +01:00
Miroslav Stampar
d7f0da5599
Minor patch for an Issue #646
2014-03-20 13:08:28 +01:00
Miroslav Stampar
97fe5e52c2
Fix for an Issue #644
2014-03-18 16:41:05 +01:00
Miroslav Stampar
97f603af4a
Fix for an Issue #641
2014-03-17 20:20:25 +01:00
Miroslav Stampar
0622cdf3d8
Bug fix (credentials used in combination with request file)
2014-03-15 09:29:21 +01:00
Miroslav Stampar
3b47418a1d
Fix for an Issue #640
2014-03-14 22:20:20 +01:00
Miroslav Stampar
56d76e6bfd
Updating list of extensions to exclude from crawling
2014-03-14 21:34:16 +01:00
Miroslav Stampar
be3fd8bb29
Fix for an Issue #638
2014-03-14 16:44:56 +01:00
Miroslav Stampar
ae36c08f12
Updating server signatures
2014-03-13 10:05:56 +01:00
Miroslav Stampar
17742df0fa
Update for an Issue #636 (to prevent eventual future reports with lack of stack trace)
2014-03-11 21:18:31 +01:00
Miroslav Stampar
2f8846caec
Fix for an Issue #636
2014-03-11 21:11:51 +01:00
Miroslav Stampar
d1a6a775f1
Patch for an Issue #636
2014-03-11 21:00:15 +01:00
Miroslav Stampar
fca57da1cf
Fix for --tables on HSQLDB
2014-03-07 15:57:41 +01:00
Miroslav Stampar
f1f53a5841
Minor cosmetic update
2014-03-06 21:08:31 +01:00
Miroslav Stampar
490d51258e
Raising number of minimum time responses (15 is statistically too low)
2014-03-03 20:49:58 +01:00
Bernardo Damele
1d7e804c1d
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2014-02-27 15:02:43 +00:00
Bernardo Damele
07a22070d8
updated signatures for test environment
2014-02-27 15:02:33 +00:00
Miroslav Stampar
291a0d772a
Update for an Issue #615
2014-02-27 14:23:14 +01:00
Miroslav Stampar
2ffdee5733
Bug fix for PAYLOAD.WHERE.REPLACE payloads containing custom injection marker ([ORIGVALUE] was screwed)
2014-02-26 11:41:48 +01:00
Miroslav Stampar
cc62a8adc9
Bug fix for JSON-like data (proper escaping of quotes)
2014-02-26 09:30:37 +01:00
Miroslav Stampar
6369a38ebc
Adding support for JSON-like data with single quote
2014-02-26 08:56:17 +01:00
Miroslav Stampar
465f968be6
Minor cosmetic update
2014-02-26 08:41:23 +01:00
Miroslav Stampar
edc8ef9d5b
Patch for an Issue #611 (original page used in case of tamper functions was wrong - e.g. if --tamper=base64encode was used)
2014-02-25 13:48:34 +01:00
Miroslav Stampar
2a423d61ef
Raising number of requests for false positive testing in case of higher levels
2014-02-23 19:40:01 +01:00
Miroslav Stampar
d405fc1157
Minor update (for the consistency sake)
2014-02-16 22:04:12 +01:00
Miroslav Stampar
58eac364a2
Bug fix
2014-02-16 21:57:14 +01:00
Miroslav Stampar
dfa727cbc5
Fix for a same bug mentioned in last commit
2014-02-16 21:47:14 +01:00
Miroslav Stampar
43df4efd11
Bug fix (bad idea is to do os.path.join on web URLs - especially on Windows OS)
2014-02-16 21:44:57 +01:00
Miroslav Stampar
d05bfdd7dd
Implementing option '--where' (Issue #605 )
2014-02-11 16:20:45 +01:00
Bernardo Damele
be6767b3b0
minor fix for command execution via web shell
2014-02-10 09:59:57 +00:00
Miroslav Stampar
fe0ff6e679
Changing 'is injectable' to 'seems to be injectable' for boolean and time-based blind injection cases - for false positive cases
2014-02-09 17:50:16 +01:00
Miroslav Stampar
8521265526
Minor fix
2014-02-07 14:40:43 +01:00
Miroslav Stampar
de8cb15350
Fix for an Issue #601
2014-02-05 15:11:39 +01:00
Miroslav Stampar
b83d531ab3
Minor fix (Reference: https://en.wikipedia.org/wiki/Internet_Information_Services )
2014-02-05 08:32:55 +01:00
Miroslav Stampar
f28b8dbda8
Minor update
2014-02-01 22:24:56 +01:00
Miroslav Stampar
534c2ee0e6
Minor update
2014-02-01 22:12:00 +01:00
Miroslav Stampar
0e44132778
Removing unused imports
2014-02-01 21:49:12 +01:00
Miroslav Stampar
f97fcb7bb3
Adding a switch --invalid-string
2014-01-23 21:56:06 +01:00
Miroslav Stampar
f88f6dcd7e
Changing --invalid-bignum from float producing to int producing
2014-01-23 09:07:25 +01:00
Miroslav Stampar
fc02badf40
Minor update
2014-01-23 08:33:21 +01:00
Miroslav Stampar
ab36e5a2f0
Fix for an Issue #597
2014-01-15 10:29:58 +01:00
Bernardo Damele
bc29bf6481
removed comments
2014-01-13 23:57:49 +00:00
Bernardo Damele
1505f1dc74
removed useless sink
2014-01-13 23:55:32 +00:00
Bernardo Damele
124ebefc7f
code cleanup
2014-01-13 23:48:15 +00:00
Bernardo Damele
4e8ab48145
fixed match
2014-01-13 23:48:00 +00:00
Bernardo Damele
b86353b485
minor fix to DB2 test case
2014-01-13 23:34:25 +00:00
Bernardo Damele
85f60d0c09
leftovers
2014-01-13 17:41:33 +00:00
Bernardo Damele
536b44a429
adapted
2014-01-13 17:38:04 +00:00
Bernardo Damele
3c79d66569
fixed stderr
2014-01-13 17:34:38 +00:00
Bernardo Damele
43a4e85749
updated copyright
2014-01-13 17:24:49 +00:00
Bernardo Damele
d546fc5ad5
slight update to regression test regexp
2014-01-13 17:24:09 +00:00
Bernardo Damele
9a1be29b45
updated test cases for regression test
2014-01-13 17:12:59 +00:00
Bernardo Damele
dfa9076a70
fixed and improved web shell upload in MySQL (it was actually broken since fc57b7565d)
2014-01-13 17:12:37 +00:00
Miroslav Stampar
6863436d4e
Implementation for an Issue #596
2014-01-13 10:05:56 +01:00
Bernardo Damele
b4139f5b82
added takeover shared object for PgSQL 9.1 Linux 32-bit - issue #20
2014-01-10 18:16:25 +00:00
Bernardo Damele
4975aafa65
updated live tests
2014-01-10 17:38:04 +00:00
Bernardo Damele
148767941b
new host
2014-01-10 17:23:27 +00:00
Bernardo Damele
d9e00adfae
minor fix
2014-01-10 17:23:16 +00:00
Miroslav Stampar
36f3ab5798
Minor bug fix (for cases when race between thread and main thread is causing server._running to not be set to True)
2014-01-09 15:46:55 +01:00
Miroslav Stampar
cb1f17cb04
Proper patch for an Issue #591
2014-01-02 12:15:56 +01:00
Miroslav Stampar
5437f8bf36
Fix for an Issue #85
2014-01-02 12:09:58 +01:00
Miroslav Stampar
4de83daf03
Minor style update
2014-01-02 11:06:19 +01:00
Miroslav Stampar
e0143e397a
Consistency fix (down below we use direct SQL)
2014-01-02 10:59:53 +01:00
Miroslav Stampar
0b4fcb6845
Fix for an Issue #591
2014-01-02 10:55:40 +01:00
Miroslav Stampar
854a55166c
Fix for an Issue #588
2014-01-02 10:29:10 +01:00
Miroslav Stampar
9b4b070ecf
Minor cosmetics
2014-01-02 10:05:58 +01:00
Miroslav Stampar
192a911b76
Patch for an Issue #28
2013-12-29 16:16:50 +01:00
Miroslav Stampar
41d6c1af82
Patch for an Issue #589
2013-12-28 13:47:40 +01:00
Miroslav Stampar
6c80f2903b
Patch for an Issue #564
2013-12-27 11:02:59 +01:00
Miroslav Stampar
178056968f
Cleaning a leftover (deleted) made for Issue #564
2013-12-27 10:49:15 +01:00
Miroslav Stampar
cadbddd607
Adding a boundary proposed in Issue #564
2013-12-27 10:46:18 +01:00
Miroslav Stampar
7718edac9b
Fix for an Issue #570
2013-12-27 09:40:33 +01:00
Miroslav Stampar
02de2aee6d
Patch for an Issue #582
2013-12-26 22:27:04 +01:00
Miroslav Stampar
ab64d385d6
Bug fix (stacked queries as in PgSQL and MsSQL DNS tunneling queries MUST end with the comment - not the recognized underlying technique's suffix)
2013-12-25 22:18:57 +01:00
Miroslav Stampar
2c2667b2be
Minor patch for an Issue #575
2013-12-18 00:56:24 +01:00
Miroslav Stampar
fd6dcd8bf5
Merge pull request #583 from mattoufoutu/api
...
RESTful API improvements
2013-12-17 14:10:19 -08:00
Miroslav Stampar
9ead80d707
Minor patch for Issue #585
2013-12-17 09:39:43 +01:00
Miroslav Stampar
f18abb1e9c
Minor update (proxy can be also a https one (e.g. Burp for HTTPS targets)
2013-12-17 09:30:51 +01:00
Miroslav Stampar
7d8eb148ce
Patch for an Issue #565 (DuckDuckGo doesn't like identity encoding)
2013-12-17 09:30:04 +01:00
Miroslav Stampar
4819e19200
Patch for an Issue #584
2013-12-16 22:00:47 +01:00
Mathieu Deous
4c9456dd72
moar logging!
2013-12-15 16:59:47 +01:00
Mathieu Deous
438ad73016
avoid names shadowing
2013-12-15 09:22:01 +01:00
Mathieu Deous
eda9a3da67
all instance attributes should be defined in constructor
2013-12-15 09:16:38 +01:00
Mathieu Deous
3effaee2a1
avoid using global variables, use a "store" class
2013-12-15 00:19:58 +01:00
Mathieu Deous
c70f2a4e6d
unused imports
2013-12-15 00:00:08 +01:00
Mathieu Deous
aa02019638
return file content in a json message when calling download endpoint
2013-12-14 16:33:17 +01:00
Mathieu Deous
c87ad1bab5
make returned values more coherent
2013-12-14 16:22:30 +01:00
Mathieu Deous
72137e85f9
do not reset options when firing a scan
2013-12-14 15:59:47 +01:00
Mathieu Deous
af7ad31182
fix commit method usage (belongs to connection, not cursor)
2013-12-14 15:58:09 +01:00
Mathieu Deous
c5a3f54b89
remove unused imports
2013-12-14 15:47:26 +01:00
Mathieu Deous
8a946509b9
PEP8
2013-12-14 15:44:10 +01:00
Miroslav Stampar
5b2ded0b18
Fix for an Issue #577
2013-12-13 21:00:26 +01:00
Miroslav Stampar
437278e32d
Fix for an Issue #580
2013-12-13 19:48:05 +01:00
Miroslav Stampar
93628cdd62
Merge pull request #578 from mattoufoutu/master
...
api's get_option function doesn't lookup the right object
2013-12-09 04:52:34 -08:00
Mathieu Deous
c3dd6e1e32
api's get_option function doesn't lookup the right object
2013-12-08 17:46:02 +01:00
Bernardo Damele
a06a6de193
minor bug fix
2013-12-06 13:26:34 +00:00
Miroslav Stampar
b7244a07cb
Changing testing payload for MsSQL (BINARY_CHECKSUM seems to be blocked in some cases)
2013-12-04 11:32:42 +01:00
Miroslav Stampar
b0ca34ff27
Bug fix (payload character '=' was not being url-encoded in custom (user) post cases - when posthint was None)
2013-12-04 10:09:54 +01:00
Miroslav Stampar
bf3fbb0ae0
Ignore Google analytics cookies
2013-12-04 09:56:37 +01:00
Miroslav Stampar
dd2ddec79a
Minor fix (better extraction of original value in case of replacement and custom POST injection mark)
2013-12-03 13:37:04 +01:00
Miroslav Stampar
59d667d94c
Minor update
2013-12-01 22:25:12 +01:00
Miroslav Stampar
663b1e711b
Bug fix
2013-12-01 21:22:29 +01:00
Miroslav Stampar
07bd22fa80
Minor fix
2013-12-01 21:03:30 +01:00
Miroslav Stampar
7054586e8a
Update for an Issue #565 (more work TBD - DuckDuckGo has some kind of IP blocking mechanism)
2013-11-25 20:57:07 +01:00
Miroslav Stampar
24e67289c8
Bug fix
2013-11-25 11:57:20 +01:00
Miroslav Stampar
cda27ec20b
Patch for an Issue #563
2013-11-24 15:01:51 +01:00
Bernardo Damele
59b6791faa
minor improvement
2013-11-19 00:24:47 +00:00
Bernardo Damele
c37ad88283
minor bug fix
2013-11-13 14:34:19 +00:00
Miroslav Stampar
3c67ba08c5
Minor fix
2013-11-12 14:53:05 +01:00
Miroslav Stampar
354aaeae5b
Removing unused imports
2013-11-12 14:11:07 +01:00
Miroslav Stampar
d84ddf23bd
Replacing os.sep constructs with os.path.join
2013-11-12 14:08:41 +01:00
Miroslav Stampar
2f1607b4d5
Minor fix for dumping non-alphanumeric database names
2013-11-12 13:13:47 +01:00
Miroslav Stampar
abd76081e1
Adding a new WAF script (varnish.py)
2013-11-11 09:25:42 +01:00
Miroslav Stampar
3ff01f5777
Adding new tamper script
2013-11-09 00:23:34 +01:00
Miroslav Stampar
0a4512e9ae
Implementation for an Issue #557
2013-11-08 09:23:38 +01:00
Miroslav Stampar
ae4cd2ebed
Minor update
2013-11-07 08:29:32 +01:00
Miroslav Stampar
48bd2e75e9
Minor patch
2013-10-28 13:59:38 +01:00
Miroslav Stampar
7ed05f01b3
Minor update
2013-10-27 00:24:57 +02:00
Miroslav Stampar
fabbe63f00
Proper fix for re.sub() call with repl value containing backslash
2013-10-23 18:07:38 +02:00
Miroslav Stampar
28529a92a7
Minor fix (for parameters with \ in value)
2013-10-23 10:49:50 +02:00
Miroslav Stampar
9f21406a4b
Using cPickle in BigArray (faster and potentially less memory used)
2013-10-21 20:48:00 +02:00
Miroslav Stampar
8dac47f7e5
Minor patch (for recognition of x-mac-turkish codec)
2013-10-21 20:04:48 +02:00
Miroslav Stampar
e197720def
Fix for an Issue #546
2013-10-19 20:54:52 +02:00
Miroslav Stampar
2ee4b81a6e
Minor fix
2013-10-18 15:59:25 +02:00
Miroslav Stampar
777d999e71
Minor update
2013-10-18 15:39:46 +02:00
Miroslav Stampar
5aaf18f556
Minor update
2013-10-18 15:26:55 +02:00
Miroslav Stampar
7104e00c95
Minor update
2013-10-18 14:47:11 +02:00
Bernardo Damele
378ce46061
NVARCHAR is not supported on Sybase Adaptive Server
2013-10-18 12:23:50 +01:00
Miroslav Stampar
6ff2b931ff
Another patch for an Issue #545
2013-10-17 23:42:51 +02:00
Miroslav Stampar
334c698d53
Adding change verbosity level in testing phase when Ctrl+C pressed
2013-10-17 16:54:53 +02:00
Miroslav Stampar
304c9822bd
Patch for an Issue #545
2013-10-17 16:38:07 +02:00
Miroslav Stampar
7cb7c6361f
Minor fix (Sybase Adaptive Server Anywhere doesn't have support for tempdb_id())
2013-10-17 16:04:55 +02:00
Miroslav Stampar
5b8d631dc0
Minor update
2013-10-16 11:48:00 +02:00
Miroslav Stampar
04dbee3bec
Update for a more generic JSON recognition regex
2013-10-16 11:39:04 +02:00
Miroslav Stampar
ebccba922b
Fix for an Issue #543
2013-10-16 11:25:55 +02:00
Bernardo Damele A. G.
72c79a4891
Merge pull request #544 from moshekaplan/patch-1
...
Correcting minor typos
2013-10-15 12:28:39 -07:00
Moshe Kaplan
8cd641a2a6
minor typos corrected
...
"choosen" -> "chosen"
2013-10-15 13:26:24 -04:00
Miroslav Stampar
d7906e8f18
Minor fix
2013-10-15 09:49:27 +02:00
Miroslav Stampar
344d3f4b5f
Minor patch
2013-10-12 21:05:18 +02:00
Miroslav Stampar
b8d49c2ea2
Minor usability patch
2013-10-12 20:41:25 +02:00
Miroslav Stampar
98d27ef200
Bug fix (missing permissions when creating dump directory)
2013-10-11 21:17:12 +02:00
Miroslav Stampar
16e803c3ca
Merge pull request #539 from bbuchacher/master
...
Fix - Custom objects cannot be serialized in JSON
2013-10-11 00:10:15 -07:00
Ben Buchacher
54a6c01005
Fix - Custom objects cannot be serialized in JSON
...
Custom objects cannot be serialized in JSON, convert tasks into list before serializing.
2013-10-10 16:06:29 -07:00
Miroslav Stampar
4c39235c2f
Minor revert (5->3)
2013-10-11 00:39:44 +02:00
Miroslav Stampar
6305c1e703
Making a comma-less RLIKE payload
2013-10-11 00:39:11 +02:00
Miroslav Stampar
dbaa35f9fe
Minor fix
2013-10-10 23:53:43 +02:00
Miroslav Stampar
2dc570d7a8
Minor patch (for ORDER BY 'col' cases)
2013-10-10 23:08:20 +02:00
Miroslav Stampar
dd87233fe4
Minor patch (to accept * inside urls in request files too)
2013-10-10 15:04:48 +02:00
Miroslav Stampar
369006ca73
Bug fix
2013-10-07 12:54:25 +02:00
Bernardo Damele
7e35eb08d2
minor update
2013-10-07 11:39:23 +01:00
Bernardo Damele A. G.
53b07c5398
Merge pull request #536 from za/master
...
adding more words at site:id common-columns
2013-10-06 22:33:48 -07:00
Zaki Akhmad
3f71c77601
adding more words at site:id common-columns
2013-10-07 10:26:16 +07:00
Miroslav Stampar
18d9e1dbc3
Minor update due to reported (debug) problems with SSLv23
2013-10-04 10:53:49 +02:00
Miroslav Stampar
a944028114
Revert of last commit
2013-10-02 22:14:50 +02:00
Miroslav Stampar
9ceb518a50
Minor patch
2013-10-02 22:03:53 +02:00
Miroslav Stampar
8e2f4669d8
Removing dependency for bz2 as there are some reported problems with the library on non-standard platforms
2013-10-02 20:32:18 +02:00
Miroslav Stampar
45c88b36c6
Fix for an Issue #532
2013-09-30 09:33:39 +02:00
Miroslav Stampar
1f2e5a91b5
Merge pull request #530 from za/master
...
add site:id common-columns
2013-09-26 06:41:09 -07:00
Zaki Akhmad
53a2fc23a0
add site:id common-columns
2013-09-26 20:32:58 +07:00
Miroslav Stampar
6f2c89bd7c
Fix for an Issue #529
2013-09-25 10:22:23 +02:00
Miroslav Stampar
2fbd7e8929
Minor fix
2013-09-24 21:56:40 +02:00
Miroslav Stampar
df9b1d72de
Minor update
2013-09-24 21:44:59 +02:00
Miroslav Stampar
099e931a15
Minor fix
2013-09-21 12:24:49 +02:00
Miroslav Stampar
31684dbc89
Fix for an Issue #524
2013-09-13 16:16:46 +02:00
Miroslav Stampar
f11e15a180
Minor update
2013-09-11 23:22:10 +02:00
Miroslav Stampar
a3defc175d
Fix (we are not using certificate but PEM private key file in this particular authentication; also, auxiliary cert_file is holding certificate chain that is ignored by python itself)
2013-09-11 23:17:18 +02:00
Miroslav Stampar
176f744ac6
Minor cosmetic update
2013-09-11 15:05:37 +02:00
Miroslav Stampar
696fb6530e
Cosmetic fix (Kali shows ugly 'python ./sqlmap.py' in usage)
2013-09-11 14:57:38 +02:00
Miroslav Stampar
96ccdb7c83
Adding new regular expressions for error messages
2013-09-06 19:41:40 +02:00
Miroslav Stampar
4cf49bc0cc
Minor fix for an Issue #517
2013-09-05 09:22:11 +02:00
Miroslav Stampar
b17bb07301
Minor regex update
2013-09-04 19:28:59 +02:00
Miroslav Stampar
bf57f636a3
Fix for an Issue #517
2013-09-04 19:22:24 +02:00
Miroslav Stampar
6a3d804af5
Minor update (display NULL instead of FALSE when non-query statement is sqlQueried)
2013-09-02 11:32:32 +02:00
Miroslav Stampar
81409ce6da
Minor patch
2013-09-02 10:54:32 +02:00
Miroslav Stampar
dd39913cf6
Improvement for an --eval mechanism
2013-08-31 00:28:51 +02:00
Miroslav Stampar
3a57af1452
Minor fix
2013-08-30 15:26:03 +02:00
Miroslav Stampar
9e975210ac
Implementation for an Issue #515
2013-08-30 10:22:43 +02:00
Miroslav Stampar
e0bfb0503c
Minor language update
2013-08-30 09:55:57 +02:00
Miroslav Stampar
28eca2116f
Fix for an Issue #513
2013-08-27 13:55:38 +02:00
Miroslav Stampar
7cb3ea20dd
Minor patch for a problem noticed yesterday too (in some cases if Ctrl-C is pressed sent is most probably a None value)
2013-08-23 11:59:58 +02:00
Miroslav Stampar
88b992ad83
Fixing a bug noticed during the yesterday's AppSecEU presentation (--headers='user-agent:foobar*' was not working properly)
2013-08-23 11:54:08 +02:00
Miroslav Stampar
3bbe02a714
Bug fix (0 datetime value not liked by direct connector)
2013-08-22 12:05:59 +02:00
Miroslav Stampar
0cf2bdeb1c
Minor language update
2013-08-22 11:11:30 +02:00
Miroslav Stampar
bc19f40d09
Minor update
2013-08-22 10:44:21 +02:00
Miroslav Stampar
7725695f26
Fix for an Issue #511
2013-08-21 11:25:41 +02:00
Miroslav Stampar
1d4e2d151d
Fix for a socks module - proper unwrapmodule (Issue #58 )
2013-08-20 19:48:03 +02:00
Miroslav Stampar
23f2c5f166
Finishing implementation for an Issue #58
2013-08-20 19:35:49 +02:00
Miroslav Stampar
c586559e30
Patch for an Issue #510
2013-08-20 18:54:32 +02:00
Miroslav Stampar
6cc0cf3702
Minor comment update
2013-08-20 18:36:31 +02:00
Miroslav Stampar
5721f6007e
Fix for an Issue #509
2013-08-18 01:24:40 +02:00
Miroslav Stampar
1f2c8fbf59
Fix for an Issue #500
2013-08-13 20:40:36 +02:00
Miroslav Stampar
38ee95e2c9
Minor language update
2013-08-13 18:58:24 +02:00
Miroslav Stampar
52a71546d0
Implementation for an Issue #507
2013-08-13 18:55:23 +02:00
Miroslav Stampar
4929cff0c0
Minor update
2013-08-13 06:42:49 +02:00
Miroslav Stampar
bfc3094e35
Merge pull request #506 from bladeswords/patch-1
...
Remove debugging which prevents sqlmap from running smoothly
2013-08-12 21:38:59 -07:00
bladeswords
6d756317c3
Remove debugging which prevents sqlmap from running smoothly
2013-08-13 13:58:45 +10:00
Miroslav Stampar
b2855e0281
Minor patch
2013-08-12 14:25:51 +02:00
Miroslav Stampar
a711c9ed36
Minor cleanup and initial work for #58
2013-08-09 14:13:48 +02:00
Miroslav Stampar
4beef0900d
Minor language fix (we support SOCKS proxy settings too)
2013-08-09 13:58:42 +02:00
Miroslav Stampar
1088011bf0
Adding new binary file formats for excluding in crawling
2013-08-02 23:07:13 +02:00
Miroslav Stampar
32c1cb20f5
Fix for an Issue #497
2013-08-01 19:48:20 +02:00
Miroslav Stampar
953b5815d8
Implementation for an Issue #496
2013-07-31 21:15:03 +02:00
Miroslav Stampar
6b826ef64d
Reintroducing option --cookie-del
2013-07-31 20:41:19 +02:00
Miroslav Stampar
ca44b23d20
Implementation for --eval to support cookies
2013-07-31 17:29:16 +02:00
Miroslav Stampar
02da417b23
Fix for a tamper script (in some cases comments were not inserted)
2013-07-31 09:52:10 +02:00
Miroslav Stampar
eaacbe0b12
Minor language fix
2013-07-31 09:24:34 +02:00
Miroslav Stampar
941b2387c0
Minor fix
2013-07-31 09:22:45 +02:00
Miroslav Stampar
4f58e0af0c
Minor fix
2013-07-31 08:45:04 +02:00
Miroslav Stampar
a585aa4bff
Adding support for ~
2013-07-29 20:42:29 +02:00
Miroslav Stampar
de31688c4f
Update for an Issue #481
2013-07-29 18:25:27 +02:00
Miroslav Stampar
b921ff0729
Fix for an Issue #495
2013-07-27 11:20:43 +02:00
Miroslav Stampar
df5a6beb6e
Queries for Issue #481
2013-07-27 11:11:11 +02:00
stamparm
dbb0d7f700
Important fix (Issue #489 ) - we had a bad presumption than only public schema could be used for enumeration (while all schemas inside a current db could be used)
2013-07-19 13:24:35 +02:00
stamparm
86b62dc619
Adding a new WAF script
2013-07-18 16:17:28 +02:00
stamparm
28cd50b2f1
Patch for an Issue #490
2013-07-16 14:08:32 +02:00
stamparm
e6f71c2130
Making 10% less requests in futile higher level/risk runs (using static template payloads for where==NEGATIVE)
2013-07-15 16:24:49 +02:00
stamparm
c9d3974205
Minor fix (templatePayload had duplicate string patterns for where==NEGATIVE)
2013-07-15 13:54:02 +02:00
stamparm
ac2d40e259
Revert of last commit (there is a chance that that big integer value is really valid :)
2013-07-15 13:34:38 +02:00
stamparm
a097ee1505
Switching --invalid-bignum to a pure integer constant (more generic - more statements require pure integer constant)
2013-07-15 13:31:56 +02:00
Miroslav Stampar
a639dbbeab
Now version check works against Python 2.5 too
2013-07-13 17:28:03 +00:00
Miroslav Stampar
f54082111d
Better way how to deal with required extensions
2013-07-13 19:25:49 +02:00
Miroslav Stampar
3f6d4083a7
Minor language update
2013-07-13 17:19:16 +02:00
Miroslav Stampar
31efabfca1
Appropriate error messaging when one of core libraries are missing due to erroneous Python build
2013-07-13 16:07:36 +02:00
Miroslav Stampar
4d9f8ad0dd
Commit related to the last one
2013-07-13 12:00:03 +02:00
Miroslav Stampar
89d8512edc
Moving bz2 into the cloak functions itself as it's not available by default in custom built Python installations (if not pre-installed libbz2-dev)
2013-07-13 11:50:03 +02:00
stamparm
dc1623a40f
Fix for a bug reported over ML (error: unbalanced parenthesis)
2013-07-11 10:20:58 +02:00
stamparm
01159575b2
Fix for an Issue #488
2013-07-11 10:11:43 +02:00
stamparm
1ae68b9bb3
Update for an Issue #405 (fix for usage of old 'complete' data from previous runs)
2013-07-10 17:18:09 +02:00
stamparm
f6c7b398fd
Update for an Issue #405 (fix for persistent options problem)
2013-07-10 16:57:44 +02:00
stamparm
aad102378a
Fix for an Issue #487
2013-07-09 11:00:43 +02:00
stamparm
be5ce760b6
Fix for an Issue #485 (failing back to single-thread mode if over some bisection length)
2013-07-09 10:24:48 +02:00
stamparm
d7c0805e7c
Removing leftover
2013-07-08 12:45:02 +02:00
stamparm
a548eb5c70
Minor text update
2013-07-08 12:44:14 +02:00
stamparm
d0e79a4d15
Minor text update
2013-07-08 12:38:36 +02:00
stamparm
a530817727
Minor typo fix
2013-07-08 11:52:46 +02:00
stamparm
8d3435ab0b
Removing reflective warning for parsing heuristic test
2013-07-08 11:48:33 +02:00
stamparm
27bf37e741
Updating to higher levels for HSQLDB specific payloads (like for e.g. Firebird)
2013-07-04 15:41:08 +02:00
stamparm
db536427f0
Adding a question for storing hashes to a temporary file (after a mention of it on Twitter)
2013-07-04 15:34:00 +02:00
stamparm
e498694928
Fix for a NoneType/--columns issue reported over ML
2013-07-02 15:02:07 +02:00
Bernardo Damele
5882ab59d8
fixed #478
2013-07-01 22:30:59 +01:00
stamparm
f97b35dcc1
Patch for an Issue #475
2013-07-01 13:43:38 +02:00
Bernardo Damele
9a8bec760f
added fingerprint for HSQLDB based on Tomcat stacktrace message
2013-07-01 12:17:52 +01:00
stamparm
b9491317a6
Minor update (Issue #475 )
2013-07-01 13:11:16 +02:00
stamparm
925098686d
Minor fix
2013-07-01 13:05:57 +02:00
stamparm
017ce22a2f
Minor consistency patch (Issue #475 )
2013-07-01 13:01:53 +02:00
stamparm
e3124b9176
Replacing tabs with spaces (Issue #475 )
2013-07-01 12:56:34 +02:00
Bernardo Damele
cfbed43066
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-07-01 11:54:35 +01:00
Bernardo Damele
6468211f65
tables and databases names on MSQLDB are capitalized
2013-07-01 11:54:31 +01:00
stamparm
5ff09aff63
Some more adjustments (Issue #475 )
2013-07-01 12:50:12 +02:00
Bernardo Damele
2ca5df2802
minor fix
2013-07-01 11:31:28 +01:00
stamparm
04046f38eb
Minor update (Issue #475 )
2013-07-01 12:26:57 +02:00
stamparm
4fb33bb26c
Some more cleanup (Issue #475 )
2013-07-01 12:11:09 +02:00
stamparm
b5e644694a
Minor cleanup
2013-07-01 12:05:02 +02:00
stamparm
f7d15cb465
Official naming is HSQLDB (and/or HyperSQL)
2013-07-01 11:57:47 +02:00
Miroslav Stampar
aeb83ba651
Merge pull request #475 from Meatballs1/hsql_clean
...
HSQL Payloads and Query Support
2013-07-01 02:38:04 -07:00
Miroslav Stampar
a1842f44f5
Fix for an Issue #477
2013-06-29 20:55:48 +02:00
stamparm
991cafc4e4
Minor refactoring
2013-06-26 13:53:42 +02:00
stamparm
c83cca4cd4
Minor patch
2013-06-26 13:49:34 +02:00
stamparm
fd5b665f7d
Removing arithmetic operations from false positive checking to minimize affect of character filtering ('>' and '=' have to stay because those are minimal requirements)
2013-06-26 10:55:34 +02:00
Meatballs
eb2012c599
Fix escaper
2013-06-24 23:50:33 +01:00
Meatballs
4595b2c287
decodeHexValue
2013-06-24 23:45:39 +01:00
Meatballs
5b6c01d739
Escaper
2013-06-24 23:41:45 +01:00
Meatballs
604694c0e5
Cleanup queries.xml
2013-06-24 23:22:52 +01:00
Meatballs
09e1dc814d
Fix concat
2013-06-24 23:20:34 +01:00
Meatballs
ed40a76c9d
Fix dummy table
2013-06-24 23:18:47 +01:00
Meatballs
a393b17513
modify fingerprint value
2013-06-24 15:12:37 +01:00
Meatballs
55a37183d4
Cleanup payloads file
2013-06-24 15:04:52 +01:00
Meatballs
550693032b
Remote whitespace in databases.py
2013-06-24 15:03:08 +01:00
Meatballs
9212b05eeb
Add call to execute statements
2013-06-24 15:01:44 +01:00
Meatballs
b886e47b6d
Add unimplemented files
2013-06-24 14:53:41 +01:00
Meatballs
62000c6406
Remaining files
2013-06-24 14:42:58 +01:00
Meatballs
7b6cc3d183
Add hsql settings
2013-06-24 14:38:44 +01:00
Meatballs
20a5d9a16e
Include HSQL dummy table
2013-06-24 14:37:42 +01:00
Meatballs
355d3f86be
hsql payloads and queries xml
2013-06-24 14:34:54 +01:00
Meatballs
d739d5062d
hsql plugin folder
2013-06-24 14:34:25 +01:00
Miroslav Stampar
0355e29b7c
Minor fix (NoneType has no attribute split)
2013-06-24 14:49:53 +02:00
Miroslav Stampar
95ed6b7203
Minor patch (Issue #470 )
2013-06-24 14:37:45 +02:00
Miroslav Stampar
4336a8fa7c
Fix for overnight (previously removed : from prefix/suffix was important for XMLType payload)
2013-06-24 14:18:42 +02:00
Miroslav Stampar
fca6772df6
Implementation for an Issue #468
2013-06-22 00:13:46 +02:00
Bernardo Damele
a72096a345
slightly more appropriate definition of output variable
2013-06-19 20:25:01 +01:00
Bernardo Damele
cae108d9fc
careful at merging pull requests with TABs ( #466 )
2013-06-19 19:49:53 +01:00
stamparm
a53823f9b7
Minor refactoring
2013-06-19 10:59:26 +02:00
stamparm
690645f6c7
Cosmetic fix
2013-06-19 10:50:00 +02:00
stamparm
20b8186fcc
Fix for an Issue #467
2013-06-19 10:41:58 +02:00
stamparm
a7787e83b8
Minor fix for case-insensitive union duplicates
2013-06-18 12:52:36 +02:00
Miroslav Stampar
aff7092736
Merge pull request #466 from Meatballs1/xp_cmdshell_output
...
Unable to retrieve XP_Cmdshell Output
2013-06-18 00:47:08 -07:00
stamparm
9a6f5a95f5
Minor patch for SQLAlchemy/MSSQL
2013-06-18 09:36:09 +02:00
Miroslav Stampar
92dfb0f817
Minor patch
2013-06-16 12:35:20 +02:00
Miroslav Stampar
c2dce66a46
Fix for an user reported bug (tbl can be None)
2013-06-16 12:35:05 +02:00
Meatballs
c5087399c1
Fix exception if init technique not available
2013-06-16 10:47:27 +01:00
Meatballs
2c98507f1e
Add better error msg
2013-06-16 10:27:08 +01:00
Meatballs
caa326774c
Fallback to blind
2013-06-16 10:22:20 +01:00
Miroslav Stampar
63d0e9bb12
Adding support for MsSQL >=2012 hash format (based on commit 70107f74f0be5357654f170a3f321e3e55e81881)
2013-06-13 21:50:35 +02:00
Miroslav Stampar
540493a69f
Fix for empty strings (previously '' was just removed)
2013-06-11 12:56:20 +02:00
Miroslav Stampar
f185e5cdd5
Fix for an Issue #463
2013-06-10 22:26:34 +02:00
Miroslav Stampar
cdb434805a
Using alpha character as a boundary in union/error techniques (instead of ':') to support wider range of (output filtering) cases
2013-06-10 22:14:45 +02:00
Miroslav Stampar
6f49b96a2d
Fix for an Issue #462
2013-06-10 12:20:58 +02:00
Miroslav Stampar
3583f45ee7
Fix for an Issue #461
2013-06-10 11:44:56 +02:00
Miroslav Stampar
ad07add549
Fixing MySQL/stacked payloads (also removing stacked conditional-error version as it's syntatically incorrect)
2013-06-05 14:32:06 +02:00
Miroslav Stampar
39612b5d87
Fix for an Issue #457
2013-06-04 23:46:39 +02:00
Miroslav Stampar
c1592e8508
Code refactoring (moving import ctypes to be used only when needed)
2013-06-04 22:23:44 +02:00
Miroslav Stampar
3e0f747fad
Minor fix
2013-06-04 00:05:25 +02:00
Miroslav Stampar
213d0ecfb9
Minor fix
2013-06-03 23:32:57 +02:00
Miroslav Stampar
edc9da1226
Minor refactoring
2013-06-03 15:14:56 +02:00
Miroslav Stampar
351c70b390
Locale module screws string.letters, etc. in some cases (e.g. IDLE run)
2013-06-01 14:06:58 +02:00
Miroslav Stampar
ca53dfad84
Minor fix
2013-06-01 13:44:50 +02:00
Miroslav Stampar
b7989f93c5
Trivial update regarding last commit
2013-05-30 12:04:56 +02:00
Miroslav Stampar
ed8f16e754
Minor update on user's request
2013-05-30 12:01:13 +02:00
Miroslav Stampar
12870e6ff3
Minor fix
2013-05-30 11:42:27 +02:00
Miroslav Stampar
793a8ad349
Minor fix
2013-05-30 11:38:24 +02:00
stamparm
f456b5a28d
Bug fix (this payload was also doable on MySQL - with CAST it's strictly being bound to Oracle only)
2013-05-29 17:41:42 +02:00
stamparm
f4ca4cd6c5
Minor update
2013-05-29 15:49:09 +02:00
stamparm
c3038fcb65
Minor cosmetic update
2013-05-29 15:46:59 +02:00
stamparm
8fbf4b11d2
Trivial update regarding last commit
2013-05-29 15:45:13 +02:00
stamparm
dfd6ee20bb
Patch for an Issue #454
2013-05-29 15:26:11 +02:00
stamparm
60df3e9d1e
Minor cosmetic update (displaying 'Technique: DIRECT' instead of 'Technique: None' in case of direct access)
2013-05-29 15:04:14 +02:00
stamparm
e28b056028
Dummy fix
2013-05-29 14:26:00 +02:00
stamparm
840af1fa7b
Fix for missing global name __file__
2013-05-29 10:20:43 +02:00
stamparm
6b280d8da4
Putting 2 decimal places for debug messages with performed queries (e.g. to handle a problem with 0 seconds roundup)
2013-05-28 14:40:45 +02:00
stamparm
bc4e1dab19
Getting rid of those ugly warning messages
2013-05-28 11:24:56 +02:00
Bernardo Damele A. G.
ba4ed30eed
minor update
2013-05-28 10:53:43 +02:00
Bernardo Damele A. G.
bca058e667
minor fix
2013-05-28 10:49:24 +02:00
Bernardo Damele A. G.
949d378bbd
minor update to doc
2013-05-28 10:48:09 +02:00
stamparm
659c0bb418
Minor fix
2013-05-27 10:38:47 +02:00
Miroslav Stampar
f3f752d85c
Patch for an Issue #452
2013-05-25 18:52:59 +02:00
Miroslav Stampar
a85a0e53de
Fix for an Issue 'ValueError: Invalid IPv6 URL'
2013-05-25 18:00:21 +02:00
Miroslav Stampar
e18796dbe1
Minor style update
2013-05-25 18:00:20 +02:00
Miroslav Stampar
e7ddc2fcab
Minor fix
2013-05-23 12:57:33 +04:00
Miroslav Stampar
eb8e12b7c2
Minor adjustment (for headers like 'name: http://asdas ')
2013-05-23 11:29:43 +04:00
Miroslav Stampar
19b87074c6
Minor fix
2013-05-22 23:30:33 +04:00
stamparm
1b3f1a4016
More appropriate naming (also, preventing ambiguities with --smart)
2013-05-22 23:21:43 +04:00
stamparm
4b2cf07262
Minor style update
2013-05-20 16:15:35 +02:00
Miroslav Stampar
1a4ea186ca
Consistency fix
2013-05-19 23:00:40 +02:00
Miroslav Stampar
d3ad408a21
Minor cosmetics
2013-05-19 22:17:53 +02:00
Miroslav Stampar
4f49dad2ba
Minor cosmetics
2013-05-19 01:19:54 +02:00
Miroslav Stampar
6cfcc1af63
Minor cosmetic
2013-05-19 01:17:22 +02:00
Miroslav Stampar
ea5c742595
Update (lagging checking is now always done once when time based compare is done; not only in case if statistical model is being filled)
2013-05-18 21:30:21 +02:00
Miroslav Stampar
980a0e3adb
Trivial update
2013-05-18 21:00:53 +02:00
Miroslav Stampar
1ff98c2ff9
Another minor text update
2013-05-18 21:00:11 +02:00
Miroslav Stampar
967513e1bb
Minor message update
2013-05-18 20:59:23 +02:00
Miroslav Stampar
caa4ee96cd
Minor cosmetic update
2013-05-18 18:28:44 +02:00
Miroslav Stampar
6608410320
Adding a question after WAF has been identified
2013-05-18 18:26:40 +02:00
Miroslav Stampar
b2b3b3b5a6
Minor bug fix (level names not properly used in non-logger output)
2013-05-18 16:44:21 +02:00
Miroslav Stampar
f24c8c6b6b
Changing logging type to warning for parsed error messages
2013-05-18 16:17:56 +02:00
Miroslav Stampar
dcea745576
Minor update (not displaying safe enclosings in table dumps)
2013-05-18 16:13:34 +02:00
Miroslav Stampar
e528ea8208
Minor language fix
2013-05-18 16:02:34 +02:00
stamparm
03732d2592
Minor fix
2013-05-17 16:04:05 +02:00
stamparm
b26ecfe087
Patch for an Issue #449
2013-05-17 15:14:51 +02:00
stamparm
76b4e1ccb9
Implementation for an Issue #450
2013-05-17 15:04:25 +02:00
stamparm
7ba9e75c97
Minor update related to the last commit
2013-05-16 15:23:20 +02:00
stamparm
7ea8dd9428
MySQL is specific (types are automatically being converted without any warning/error)
2013-05-16 15:12:36 +02:00
stamparm
f1f34a65a2
Minor update
2013-05-15 13:38:26 +02:00
stamparm
41f0e91662
Minor update (related to last commit)
2013-05-13 14:50:03 +02:00
stamparm
cb9ea67c8d
Code refactoring (moving progress.py to lib/utils)
2013-05-13 14:48:39 +02:00
stamparm
936815128d
Minor fix
2013-05-13 13:42:43 +02:00
Miroslav Stampar
034e123b0c
Minor fix (to accept -p cookie without need for raising --level / as it's already done for referer and user_agent)
2013-05-12 16:24:13 +02:00
Miroslav Stampar
b8ab37651c
Minor update (tested against LAMP - %A0 makes problems)
2013-05-12 15:21:56 +02:00
Miroslav Stampar
6676eaf88f
Minor fix
2013-05-12 14:02:50 +02:00
Miroslav Stampar
d34286fe44
Temporary disabling
2013-05-12 13:45:32 +02:00
Miroslav Stampar
f8cef1fc6f
Minor fix for a test case 211
2013-05-09 21:20:17 +02:00
stamparm
8b64709c17
Completing implementation for an Issue #189 (union)
2013-05-09 16:36:03 +02:00
stamparm
3873805dab
Partial implementation for an Issue #189 (error-based; still partial union left)
2013-05-09 16:23:57 +02:00
stamparm
9fe5a8832f
Update for an Issue #189 (code refactoring of ProgressBar so it could be ready for usage in non-inference cases out of box)
2013-05-09 15:52:18 +02:00
stamparm
fc57b7565d
Implementation for an Issue #432
2013-05-09 14:26:29 +02:00
stamparm
03be419d5d
Fix for an Issue #447
2013-05-07 13:25:30 +02:00
Miroslav Stampar
427d88b194
Minor overnight fix
2013-05-04 11:39:23 +02:00
stamparm
2bfdac5ebc
Minor update for crawler
2013-04-30 18:32:46 +02:00
stamparm
887109a12d
Minor bug fix (for not displaying heuristic detected page charset None)
2013-04-30 18:16:32 +02:00
stamparm
ebe8ee3500
Fix for crawler and redirection case
2013-04-30 18:08:26 +02:00
stamparm
09e7f4f697
Minor bug fix regarding traffic logging of redirected requests
2013-04-30 17:46:26 +02:00
stamparm
3c110b3620
Minor bug fix
2013-04-30 16:40:16 +02:00
stamparm
bdb9219e9b
Minor revert
2013-04-30 14:41:38 +02:00
stamparm
d2a5548889
Some more reordering
2013-04-30 14:32:11 +02:00
stamparm
16866119b8
Another minor update
2013-04-30 14:11:56 +02:00
stamparm
08fbfda5d2
Minor update
2013-04-30 14:06:04 +02:00
stamparm
69e3a2cb9e
Minor update
2013-04-30 14:06:04 +02:00
stamparm
03c4eb8338
Minor update
2013-04-30 14:06:04 +02:00
stamparm
214d9aaf4b
Language fix
2013-04-30 14:06:04 +02:00
stamparm
3266c6c1f1
Language fix
2013-04-30 14:06:04 +02:00
Bernardo Damele
96847de370
updated doc
2013-04-30 11:53:52 +01:00
Bernardo Damele
4f88fcf7b3
updated doc
2013-04-30 11:44:55 +01:00
Bernardo Damele
9f1e644f23
language fixes
2013-04-30 11:44:47 +01:00
stamparm
46557198a5
Minor update of doc root names
2013-04-29 11:29:59 +02:00
Miroslav Stampar
8817a2d657
Update README.md
2013-04-29 12:14:48 +03:00
stamparm
1035ee9c3d
Patch for an Issue #442
2013-04-26 14:49:24 +02:00
Miroslav Stampar
beab72a180
Minor language update
2013-04-25 19:55:45 +02:00
stamparm
ff62b0d3ea
Replacing a substring query for PgSQL with a non-comma version (there are no compatibility issues while skipping problems with possible comma filtering)
2013-04-25 10:14:03 +02:00
stamparm
63d7707346
Adding support for appending to the existing table dump if --start/--stop is used
2013-04-24 16:08:40 +02:00
stamparm
e3a02f56e6
Just in case for --force-ssl (if url is returned in e.g. refresh toward the target)
2013-04-24 12:35:39 +02:00
stamparm
42a73d8e0b
Minor language update
2013-04-24 12:10:06 +02:00
stamparm
8d382f00e8
Minor style update
2013-04-22 11:38:47 +02:00
Miroslav Stampar
a475116853
Minor check
2013-04-21 21:42:23 +02:00
stamparm
0d92145fc6
Minor bug fix
2013-04-19 15:40:25 +02:00
stamparm
6e0aaafdea
Fix for an Issue #438
2013-04-19 10:14:28 +02:00
stamparm
0cb3ce5765
Bug fix (maybe it will have repercusions in future as this was a silent bug)
2013-04-19 10:10:06 +02:00
stamparm
b7d4afcc63
Moving '--pivot-column' to a General section (Issue #437 )
2013-04-18 17:12:32 +02:00
stamparm
9d045e14e8
Implementation for an Issue #437
2013-04-18 17:06:45 +02:00
stamparm
2defc30dc6
From now on --dbms-cred can be used also in combination with -d (more flexibility as spotted that one user used in that way on ML)
2013-04-17 11:12:15 +02:00
stamparm
feed2274c3
Patch for an Issue #435
2013-04-17 10:48:17 +02:00
stamparm
c73489aff3
Adding a couple of new option validation checks
2013-04-16 14:31:10 +02:00
stamparm
7204ec5616
Adding a basic validation check (-d with --url)
2013-04-16 14:23:27 +02:00
stamparm
6fed1921ed
Bug fix (there are cases when provided kwargs containing explicit None values while we want to use the alternative in those kind of cases; there was an intention in original code, while the implementation was buggy)
2013-04-16 14:17:41 +02:00
Miroslav Stampar
840ee26a14
If SQLAlchemy is available and it has problems while connecting then it should be smarter to not force the other (standard) method - if available
2013-04-15 18:42:26 +02:00
stamparm
de99717b00
Disable sqlalchemy warnings if applicable
2013-04-15 16:29:08 +02:00
stamparm
1c2197e8de
Minor bug fix for an Issue #361 (removal of that ugly garbage clean warning message after sqlmap ends)
2013-04-15 16:18:40 +02:00
stamparm
6ab2e8eca4
Trivial style update
2013-04-15 16:09:04 +02:00
stamparm
a3d36fcb73
Minor update
2013-04-15 16:07:27 +02:00
stamparm
140cffbde2
Patch for an Issue #434
2013-04-15 15:57:28 +02:00
stamparm
9ccbdb3fdf
Added a check for an Issue #361
2013-04-15 15:36:10 +02:00
stamparm
1c47b33020
Few bug fixes in -d (there were late values in payloads in some cases; sqlalchemy returns RowProxy for tuple)
2013-04-15 15:23:45 +02:00
stamparm
f936746423
Code restyling
2013-04-15 14:31:27 +02:00
stamparm
aed738d6e6
Update for an Issue #361
2013-04-15 14:20:21 +02:00
stamparm
a9a0d1a3f9
Minor update
2013-04-15 11:56:19 +02:00
stamparm
10fbeaed7b
Code refactoring
2013-04-15 11:49:11 +02:00
stamparm
349f885f08
Minor patch
2013-04-15 11:41:53 +02:00
stamparm
8853e43616
Applying patch from Brandon Perry via ML
2013-04-15 11:01:07 +02:00
stamparm
3e65037a05
Introducing lib/utils/sqlalchemy.py (Issue #361 )
2013-04-15 10:33:25 +02:00
Miroslav Stampar
b6fee638ef
Neutralizing time of cookie expiration (in case of --load-cookies)
2013-04-14 01:13:08 +02:00
Miroslav Stampar
ed5599f489
In case that cookie file is given and cookie header inside request file clashes with one of contained cookies, give cookie file greater priority
2013-04-12 19:20:33 +02:00
stamparm
7edd7ee2aa
Trivial code change
2013-04-12 16:25:24 +02:00
Miroslav Stampar
73917fc9c8
Minor update (same, but safer)
2013-04-11 21:25:44 +02:00
Miroslav Stampar
0b449bb1d9
Fix for an Issue #433
2013-04-10 19:33:31 +02:00
stamparm
f67148a9a4
Update for an Issue #431
2013-04-10 16:43:57 +02:00
stamparm
661b44135d
Minor bug fix
2013-04-10 11:59:07 +02:00
stamparm
9c264e6426
Revert back of SQLite3 time-based payload as of regression test failing
2013-04-10 11:10:19 +02:00
stamparm
8c9da95343
Style and consistency update (url -> URL)
2013-04-09 11:48:42 +02:00
stamparm
3948b527dd
Update for an Issue #429
2013-04-09 11:36:33 +02:00
stamparm
91054099aa
Minor style update
2013-04-09 10:42:58 +02:00
stamparm
cce541cc33
Patch for an Issue #429
2013-04-09 10:39:20 +02:00
stamparm
33e9b3c451
Minor style update
2013-04-09 10:39:20 +02:00
Miroslav Stampar
438fd296d6
Update README.md
2013-04-08 11:41:59 +03:00
Miroslav Stampar
7614c815ed
Minor update/patch
2013-04-07 21:32:03 +02:00
Miroslav Stampar
240e9f3f7e
Minor patch
2013-04-07 11:02:43 +02:00
Miroslav Stampar
50ac3aab7a
Minor patch
2013-04-06 01:56:24 +02:00
stamparm
a75d3ed0b8
Minor style update
2013-04-06 01:56:23 +02:00
Miroslav Stampar
3794c3cc2f
Update README.md
2013-04-04 18:08:36 +03:00
Miroslav Stampar
bd5cabd975
Update README.md
2013-04-04 18:05:04 +03:00
Miroslav Stampar
976c600a83
Update README.md
2013-04-04 17:40:15 +03:00
Miroslav Stampar
df4fd82515
Minor update
2013-04-03 23:27:27 +02:00
Miroslav Stampar
c75a2d0c40
Minor patch
2013-04-03 21:31:37 +02:00
Miroslav Stampar
153aa10b77
Minor cosmetic update
2013-04-03 19:00:54 +02:00
stamparm
acc650d3dc
Minor fine tuning
2013-04-03 15:14:25 +02:00
stamparm
125168c515
Reverting back to 8002531b63 (that last 76dcbbda0f resulted in 'too big blob')
2013-04-03 14:38:13 +02:00
stamparm
76dcbbda0f
Reverting last commit and making heavy query on SQLite heavier
2013-04-03 14:23:28 +02:00
stamparm
8002531b63
Heavy queries should not have --time-sec set to some small value in live tests as their responses are machine dependent (on fast machines --time-sec=2 will result in fast responses making sqlmap life harder)
2013-04-03 14:17:13 +02:00
Miroslav Stampar
f387333415
Minor cosmetics
2013-04-02 17:34:56 +02:00
Miroslav Stampar
4b5335a323
Moving --force-ssl from [Request] to [General] options
2013-04-02 17:18:21 +02:00
Miroslav Stampar
76a0d20799
Minor patch
2013-04-01 22:18:41 +02:00
Miroslav Stampar
b67f342975
Minor patch
2013-04-01 17:32:16 +02:00
stamparm
a371f182ac
Minor patch (previous combination is not working well with oriental characters - 0 length normalized unicode string is being returned)
2013-03-28 15:37:14 +01:00
stamparm
e1ffdde532
Little cleaning a mess with url encoding and post hint types
2013-03-27 13:39:27 +01:00
Miroslav Stampar
c19a283434
Minor patch
2013-03-26 20:06:50 +01:00
stamparm
7accba4cf9
Minor update
2013-03-26 16:10:41 +01:00
stamparm
0882fe0ce3
Minor update related to the last two
2013-03-26 16:04:56 +01:00
stamparm
eb1bfc20cb
Update related to the last commit
2013-03-26 15:36:44 +01:00
stamparm
2fe6aea0eb
Minor fix
2013-03-26 15:07:14 +01:00
stamparm
825aa4b8dd
Minor language update
2013-03-26 14:27:51 +01:00
stamparm
5dd2529b02
Minor language update
2013-03-26 14:18:37 +01:00
stamparm
4d2b77dde3
Minor language update
2013-03-26 14:15:40 +01:00
stamparm
473a39b820
Minor language fix
2013-03-26 14:11:17 +01:00
stamparm
3f8dafedae
Minor text update
2013-03-26 14:08:35 +01:00
stamparm
64ba88096f
Adding a new test case (Issue #423 )
2013-03-21 12:13:13 +01:00
stamparm
ad039c335d
Implementation for an Issue #423
2013-03-21 11:28:44 +01:00
stamparm
3740a97cc9
Adding a --version switch like all command line programs have
2013-03-20 11:44:09 +01:00
stamparm
7447773237
Update for consistency (all other enums are using _ in between words)
2013-03-20 11:10:24 +01:00
stamparm
ae6ce7db30
Removal of unused imports
2013-03-20 10:44:15 +01:00
stamparm
c5573dc2d5
Update of doc/THANKS
2013-03-20 10:34:48 +01:00
stamparm
5857a09e2e
New WAF scripts
2013-03-20 10:32:15 +01:00
Miroslav Stampar
8acf033715
Code refactoring
2013-03-19 19:24:14 +01:00
Miroslav Stampar
a3d9a7b1ff
Minor fix
2013-03-19 19:06:51 +01:00
stamparm
d1ae62b22b
Patch for an Issue #422
2013-03-19 12:27:49 +01:00
stamparm
6969874c02
Switch --no-cast is incompatible with switch --hex (integer values are not being casted in case of --no-cast --hex which is causing unwanted decodings of returned values)
2013-03-19 10:52:37 +01:00
stamparm
10e6c70c22
Trivial style update (undoing last dummy commit)
2013-03-19 10:43:29 +01:00
stamparm
70265fd3b5
Trivial style update
2013-03-19 10:43:03 +01:00
stamparm
5adac57ca9
Trivial style update
2013-03-19 10:42:50 +01:00
stamparm
558ef0aaff
Minor fix
2013-03-19 10:42:20 +01:00
stamparm
e226006766
Trivial fix
2013-03-18 13:29:55 +01:00
stamparm
5e02bcbd58
Minor adjustment
2013-03-18 12:16:16 +01:00
stamparm
7111cdabe3
Minor cosmetics
2013-03-18 11:41:15 +01:00
stamparm
ba1e9aa373
Adding new WAF script
2013-03-18 11:22:30 +01:00
Miroslav Stampar
5df1f5528e
More general update for an Issue #421
2013-03-15 22:49:09 +01:00
Miroslav Stampar
f0a419bdec
Patch for an Issue #421
2013-03-15 22:08:15 +01:00
Miroslav Stampar
596cf95040
Minor fix
2013-03-15 17:22:33 +01:00
Miroslav Stampar
2938ac550c
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-03-15 17:00:15 +01:00
Miroslav Stampar
ff4e62ff90
Minor cosmetics
2013-03-15 17:00:01 +01:00
Bernardo Damele
2334e0e929
minor fix
2013-03-15 15:55:27 +00:00
Miroslav Stampar
4010df307e
Trivial cosmetics
2013-03-15 16:37:52 +01:00
Miroslav Stampar
4cb378ce3e
Another update for an Issue #352 and couple of fixes
2013-03-13 21:57:09 +01:00
Miroslav Stampar
b35122a42c
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-03-13 19:52:17 +01:00
Miroslav Stampar
eb08c8d752
Another update for an Issue #352
2013-03-13 19:42:22 +01:00
Bernardo Damele
dea62189b2
fixes #420
2013-03-12 22:16:42 +00:00
Miroslav Stampar
2f43c3eb9b
Minor fix (digest live test case) and some refactoring
2013-03-12 21:16:44 +01:00
Miroslav Stampar
65306f1ac1
Update for an Issue #352
2013-03-12 20:10:32 +01:00
Miroslav Stampar
db0a1e58b9
Update for an Issue #352
2013-03-11 14:58:05 +01:00
Miroslav Stampar
d6fc10092f
Minor refactoring
2013-03-11 13:31:50 +01:00
Miroslav Stampar
84a5bdb9cf
Trivial cosmetics
2013-03-09 19:41:24 +01:00
Miroslav Stampar
79d6a0e9c9
Using binary data in dummy mode
2013-03-09 19:40:24 +01:00
Miroslav Stampar
1e731f87a4
Patch for an Issue #419 (Authentication header is now properly being cached - no more one reauth per each request)
2013-03-09 19:33:04 +01:00
Miroslav Stampar
8e6692d793
Minor fix (for JSON values with :)
2013-03-05 20:12:24 +01:00
Bernardo Damele
30cf933445
added one more test case
2013-03-05 18:21:45 +00:00
Miroslav Stampar
e9b86350f1
Patch for an Issue #403
2013-03-05 18:32:31 +01:00
Miroslav Stampar
7190205a46
Revert of previous commit (substrings are checked too)
2013-03-05 18:26:47 +01:00
Miroslav Stampar
e050efa3e2
Minor fix (common outputs are whole string values - not partial)
2013-03-05 18:09:26 +01:00
Miroslav Stampar
62980d7d5a
Automatically decoding url encoded data in response
2013-03-05 17:32:10 +01:00
Miroslav Stampar
9e49d8c68f
Adding support for SHA2 hash functions
2013-03-05 11:04:46 +01:00
Miroslav Stampar
2ada9e9b84
Patch for an Issue Issue #416
2013-03-04 18:05:40 +01:00
Miroslav Stampar
084cfc797a
Fix for an Issue #415
2013-03-02 09:55:12 +01:00
Miroslav Stampar
e7c66a2a76
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-03-02 09:44:17 +01:00
Miroslav Stampar
333ca0369b
Merge pull request #413 from Bjerregaard/master
...
Fixed bug in false positive test for time-based injections
2013-03-02 00:43:32 -08:00
Martin Bjerregaard Jepsen
d7a77c79ad
Fixed incorrect call to checkBooleanExpression when testing for false positives
2013-03-01 22:51:34 +01:00
stamparm
46b9a602ba
Minor style update (because of consistency with other payloads; also, Oracle is uppercase oriented)
2013-03-01 12:43:08 +01:00
stamparm
3a3f9c5ea1
Trivial commit related to the last one
2013-03-01 12:09:03 +01:00
stamparm
55f33da85a
Fix for invalid logical test cases
2013-03-01 12:04:49 +01:00
stamparm
440b484bf6
Minor update (one more just in case dummy request in false positive check for time-based injections - when DBMS could be unresponsive a bit due to previous heavy-queries)
2013-03-01 10:59:04 +01:00
Miroslav Stampar
e42350ddce
Minor style update
2013-02-28 20:28:34 +01:00
Miroslav Stampar
0e89cc62a2
Adding a hidden switch --dummy used for dummy runs (getPage() returns random data) - usefull for testing purposes for skipping connections
2013-02-28 20:20:08 +01:00
Miroslav Stampar
bf05709841
Addin new WAF scripts
2013-02-28 18:54:56 +01:00
Miroslav Stampar
b5cc1a99db
Minor fix (KONA uses same core set rules)
2013-02-28 18:54:12 +01:00
stamparm
9ef79df23d
Cleaning up cases with Set-Cookie (conf.cj is handling it automatically; also, default redirector needed to be patched)
2013-02-28 13:51:08 +01:00
stamparm
aa59266804
Minor update
2013-02-27 14:28:54 +01:00
stamparm
2e2658d4fa
Adding new WAF scripts
2013-02-26 16:06:19 +01:00
stamparm
be50192d8d
Refactoring WAF scripts
2013-02-26 15:54:50 +01:00
stamparm
e5835dc74f
Update for WAF scripts
2013-02-26 15:30:11 +01:00
stamparm
6c38afab35
Minor update
2013-02-26 14:49:37 +01:00
stamparm
17fa0f568c
Minor patch for an Issue #404
2013-02-26 12:55:09 +01:00
stamparm
ecbcd4afe6
Minor update
2013-02-26 12:55:09 +01:00
Bernardo Damele
0835fb2e0f
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-26 10:20:19 +00:00
Bernardo Damele
88cda87451
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-26 10:19:23 +00:00
stamparm
2fc9396bb0
Minor fix for TrafficShield WAF script
2013-02-26 11:19:12 +01:00
stamparm
af4762ace2
Minor style update
2013-02-26 11:16:09 +01:00
Bernardo Damele
c85d57522c
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-26 10:12:25 +00:00
Bernardo Damele
34ce8742f1
removed leftover
2013-02-26 10:12:18 +00:00
stamparm
f6b43b4b13
Minor update for an Issue #290
2013-02-26 11:08:06 +01:00
stamparm
9d81be7af5
Removing redundant piece of code
2013-02-25 14:12:57 +01:00
stamparm
dc9dc233b6
Adding a comment
2013-02-25 14:07:20 +01:00
stamparm
0d2138a4a0
Minor fix for escaping unicode strings in SQLite escaper
2013-02-25 14:06:46 +01:00
stamparm
e5e39bc682
Fix for an Issue #410
2013-02-25 11:07:30 +01:00
stamparm
6fbd902265
Minor refactoring (Issue #411 )
2013-02-25 10:44:04 +01:00
stamparm
bdf72b0ffa
Minor fix
2013-02-22 17:34:53 +01:00
stamparm
7127869ede
Minor bug fix (live test specific verbosity should be valid only inside of it)
2013-02-22 17:26:48 +01:00
stamparm
68ce51bfd4
Changing from warn to info for no WAF found
2013-02-22 12:15:38 +01:00
stamparm
ad471368f5
Fixing a display bug (cases where messages are just appended after the readInput line in batch mode) introduced with b472d9809a
2013-02-22 11:42:09 +01:00
stamparm
0bbbfc2eac
Adding a small warning message (related to the Issue #407 )
2013-02-22 11:12:41 +01:00
stamparm
42cbd94fa4
Better update regarding 6acb2480b8
2013-02-22 10:49:45 +01:00
stamparm
44a46d2b10
Fix for an Issue #409
2013-02-22 10:18:22 +01:00
Miroslav Stampar
6acb2480b8
Adding WAF script for SecureIIS
2013-02-21 21:34:26 +01:00
Miroslav Stampar
c555120c1f
Adding WAF script for Microsoft ISA Server
2013-02-21 21:13:48 +01:00
Miroslav Stampar
229e4e167b
Minor cosmetics
2013-02-21 21:06:31 +01:00
Miroslav Stampar
6058eecba0
Adding WAF script for WebKnight
2013-02-21 21:04:49 +01:00
stamparm
3a8c0cd3a2
Minor style update
2013-02-21 14:52:56 +01:00
stamparm
fc554e5b99
Update for an doc/THANKS (Issue #290 )
2013-02-21 14:51:04 +01:00
stamparm
29ba43ee6c
Unhidding switch '--identify-waf' (Issue #290 )
2013-02-21 14:48:19 +01:00
stamparm
08f0670aca
Minor refactoring for an Issue #290
2013-02-21 14:39:22 +01:00
stamparm
8e49872d7c
Finalizing implementation for an Issue #290
2013-02-21 14:33:12 +01:00
stamparm
6a2129268d
Update of year in COPYING file
2013-02-21 12:48:12 +01:00
stamparm
6b2981ef4e
Update for an Issue #290 (adding tamper-like scripts into (new) directory waf)
2013-02-21 11:14:57 +01:00
Miroslav Stampar
f593e1d30f
Reverting last commit as there is bunch of similar
2013-02-20 17:35:36 +01:00
stamparm
e2b7384921
Adding a new test case (--sql-query)
2013-02-20 14:10:39 +01:00
stamparm
ba015608c6
Update for special cases
2013-02-19 10:12:47 +01:00
stamparm
69063947b6
Debug message should go with logging.DEBUG
2013-02-19 09:46:51 +01:00
Bernardo Damele
d7247a51ee
do not prompt constantly if the page is not found
2013-02-18 18:08:20 +00:00
Miroslav Stampar
6c8e8e2a0f
Minor fix
2013-02-18 15:23:55 +01:00
Miroslav Stampar
7f293afe74
Proper escaping for SQL identificators in Oracle (also, revert for 9b5f33560b)
2013-02-18 15:18:53 +01:00
Miroslav Stampar
f817105db3
Minor bug fix
2013-02-18 14:40:39 +01:00
Miroslav Stampar
75a9404cb5
Bug fix (unenclosed 'SELECT * FROM user' returns result for a system function user <- previous results were illegal)
2013-02-18 14:15:48 +01:00
Miroslav Stampar
5c099efccc
Fix for an Issue #401
2013-02-18 11:38:18 +01:00
Bernardo Damele
6bacbdb031
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-15 17:12:09 +00:00
Bernardo Damele
5abca52924
added one more test case
2013-02-15 17:11:40 +00:00
Miroslav Stampar
9b5f33560b
Oracle is too specific (only column names can be enclosed) - removing it
2013-02-15 17:36:58 +01:00
Miroslav Stampar
bf82506c1b
Oracle can't enclose table names with double quotations
2013-02-15 17:36:58 +01:00
Miroslav Stampar
1b3d749488
Proper fix related to the last commit/revert
2013-02-15 17:36:58 +01:00
Miroslav Stampar
5a793cbc7c
Minor revert
2013-02-15 17:36:58 +01:00
Miroslav Stampar
046f347f5d
Minor fix
2013-02-15 17:36:58 +01:00
Miroslav Stampar
834ae6aac0
Another minor update
2013-02-15 17:36:58 +01:00
Miroslav Stampar
799bd51c2e
Minor fix when two readInput/dataToStdout are called one at a time
2013-02-15 17:36:58 +01:00
Miroslav Stampar
97c06854a4
Minor fixes
2013-02-15 17:36:58 +01:00
Bernardo Damele
0e7f771be6
minor adjustment
2013-02-15 16:28:09 +00:00
Bernardo Damele
35aa785870
bug fix to make --predict-output work also with time-based technique
2013-02-15 16:25:33 +00:00
Miroslav Stampar
014e4e0055
Minor represenation fix
2013-02-15 14:48:24 +01:00
Miroslav Stampar
67157fa2ba
Some more minor fixes
2013-02-15 14:28:05 +01:00
Bernardo Damele
63ddeb9008
unnecessary variable
2013-02-15 13:26:28 +00:00
Miroslav Stampar
b1c0cabde5
Minor fixes
2013-02-15 14:21:51 +01:00
Miroslav Stampar
345d10a9e0
Consistency fix (everywhere else we show unsafe format of identificator names)
2013-02-15 14:05:14 +01:00
Miroslav Stampar
2fb599619a
Bug fix
2013-02-15 13:55:09 +01:00
Bernardo Damele
b472d9809a
another consistency fix to readInput()
2013-02-15 09:35:09 +00:00
Bernardo Damele
32c8c67888
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-15 09:29:41 +00:00
Bernardo Damele
20c5f9a030
consistency fix
2013-02-15 09:29:36 +00:00
Miroslav Stampar
11bcf28d86
Fix for an Issue #399
2013-02-15 10:04:13 +01:00
Miroslav Stampar
5d068896a9
Minor bug fix
2013-02-15 09:54:51 +01:00
Bernardo Damele
87db5d0dab
minor bug fix to avoid duplicates - #297
2013-02-15 00:53:05 +00:00
Bernardo Damele
c3f1e196e1
added missing parameter
2013-02-15 00:43:46 +00:00
Bernardo Damele
4727589135
code consistency
2013-02-15 00:17:13 +00:00
Miroslav Stampar
515be4ee0b
Minor just in case commit related to the last one
2013-02-14 19:58:10 +01:00
Miroslav Stampar
fef60b73f4
Minor update for proper display of [PAYLOAD] in JSON/XML/SOAP cases
2013-02-14 19:53:26 +01:00
Bernardo Damele
0c79d7b1e2
unnecessary import
2013-02-14 18:33:47 +00:00
Bernardo Damele
d8942d2ae0
fixes #396 - adapted the engine to properly verify all steps of takeover were successul, minor code refactoring too
2013-02-14 18:32:22 +00:00
Bernardo Damele
614ff6029d
working on #396 - handle the case when we dont have a web backdoor/file stager for the language API, added a few more log messages to give further information about what is going on, minor bug fix to docRoot
2013-02-14 18:31:14 +00:00
Bernardo Damele
3b38b20176
working on #396 - adaptation for the verification phase
2013-02-14 18:29:55 +00:00
Bernardo Damele
261db6ed4f
working on #396 - verify shellcodeexec executable has been properly uploaded
2013-02-14 18:29:35 +00:00
Bernardo Damele
4d5ecc3b03
working on #396 - verify icmpsh executable has been properly uploaded
2013-02-14 18:28:48 +00:00
Bernardo Damele
66cee83ca4
if needed, allow to reinitialize the environment for takeover - issue #396
2013-02-14 17:39:19 +00:00
Bernardo Damele
d91530f885
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-14 17:16:55 +00:00
Bernardo Damele
52264f544e
minor fix for Windows file paths, do not strip the windows drive letter
2013-02-14 17:16:49 +00:00
Miroslav Stampar
fdf00e4842
Fix for an Issue #397
2013-02-14 17:14:36 +01:00
Miroslav Stampar
368a2fd297
Fix for an Issue #393
2013-02-14 16:18:16 +01:00
Miroslav Stampar
f97f575018
Trivial restyling
2013-02-14 15:41:27 +01:00
Miroslav Stampar
605c5b089e
Minor style update
2013-02-14 15:38:44 +01:00
Miroslav Stampar
06d8547916
Implementation for an Issue #394
2013-02-14 15:38:44 +01:00
Miroslav Stampar
7944684ff2
This was supposed to be a separate commit (going to commit it in next one)
2013-02-14 15:38:44 +01:00
Miroslav Stampar
6c0054bc5f
Putting that ugly parameter xyz is not inside the Cookie into the debug messages
2013-02-14 15:38:44 +01:00
Bernardo Damele
d42d28392a
avoid tracebacks because the parameter does not exist
2013-02-14 13:18:33 +00:00
Bernardo Damele
c9c520a325
no need to repeat the debug message each time this function is called
2013-02-14 13:18:15 +00:00
Bernardo Damele
646df37884
minor bug fix for --reg-read
2013-02-14 13:17:30 +00:00
Bernardo Damele
f191b9bdf4
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-14 12:39:24 +00:00
Bernardo Damele
1de109747f
minor bug fix introduced in 2267dd8f47
2013-02-14 12:39:17 +00:00
Miroslav Stampar
c72353321d
Minor update for an Issue #392
2013-02-14 13:36:33 +01:00
Miroslav Stampar
0b8de94ace
Putting cases with INTO here too
2013-02-14 12:35:17 +01:00
Bernardo Damele
4b9d8ed673
reverted a previous commit as not all distributions create a link file /usr/bin/python2 to the Python interpreter
2013-02-14 11:32:17 +00:00
Bernardo Damele
2267dd8f47
working on #392 to fix --os-cmd and --os-shell output parsing
2013-02-14 11:31:20 +00:00
Bernardo Damele
cb6d549e57
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-14 11:25:12 +00:00
Bernardo Damele
a67ef4117f
make sure to use Python 2 interpreter when default system Python is version 3
2013-02-14 11:25:04 +00:00
Miroslav Stampar
efe1bf0ded
Minor fix (for those multiline cases like in MsSQL)
2013-02-14 12:20:40 +01:00
Miroslav Stampar
6629233de5
Minor update
2013-02-14 10:18:40 +01:00
Miroslav Stampar
b3b3899dab
Fix for an Issue #273 (must for MsSQL 2000; works on MsSQL > 2000)
2013-02-14 10:08:29 +01:00
Miroslav Stampar
a0b44da5d8
Minor fix for --threads>1 --binary-fields
2013-02-13 20:47:27 +01:00
Miroslav Stampar
3483fd4347
MAX not supported by MSSQL < 2005
2013-02-13 18:33:28 +01:00
Bernardo Damele
8abd014a3e
updated doc
2013-02-13 16:30:11 +00:00
Miroslav Stampar
0a4605644e
Minor fix for previous commit
2013-02-13 16:31:03 +01:00
Miroslav Stampar
2b121c938b
Minor fix
2013-02-13 16:24:21 +01:00
Miroslav Stampar
9b231f87d6
Minor bug fix (regarding Issue #379 ) - in case that two processes enter the same proc_count decrementing line sqlmap would halt
2013-02-13 15:31:50 +01:00
Miroslav Stampar
8138d1318e
Minor fix
2013-02-13 15:10:49 +01:00
Bernardo Damele
cbb5c79d29
typo fix
2013-02-13 13:07:47 +00:00
Bernardo Damele
d9e716b95d
added two debug messages for clarity
2013-02-13 12:46:45 +00:00
Miroslav Stampar
c6d29e093e
Fixing issue with newlines after the data in -r mode
2013-02-13 12:36:01 +01:00
Miroslav Stampar
965fa04a33
Trivial update
2013-02-13 12:28:51 +01:00
Miroslav Stampar
d78a3e977b
Update (allowing regular char * to be inside SOAP/JSON/XML)
2013-02-13 12:24:42 +01:00
Miroslav Stampar
6314d64a70
Renaming --binary to --binary-fields
2013-02-13 11:27:03 +01:00
Miroslav Stampar
dd6f50a00e
Removing unused imports
2013-02-13 11:15:24 +01:00
Miroslav Stampar
7c802ed8cc
Minor fix
2013-02-13 11:14:45 +01:00
Miroslav Stampar
dc41484b3f
Refactoring of funcionality for finding out if stacking is available
2013-02-13 09:57:16 +01:00
Miroslav Stampar
8b4f72322a
Adding (for now hidden) option --binary (works like -C but deliberately retrieves data in hex format and displays in hex format)
2013-02-13 09:56:44 +01:00
Miroslav Stampar
1d42aba01e
Minor update regarding 093a93938c (for goStacked to work properly with stacked conditional payloads - e.g. proper suffix/prefix)
2013-02-12 17:35:14 +01:00
Miroslav Stampar
c34f6e25b2
Minor fix for --eval (urldecoded values should be used inside evaluation)
2013-02-12 17:01:47 +01:00
Miroslav Stampar
b6f7da6832
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-12 15:49:03 +01:00
Miroslav Stampar
cf6c3a84b5
Adding support for symbolic linking sqlmap.py
2013-02-12 15:48:49 +01:00
Bernardo Damele
ae0544d05f
minor fix
2013-02-12 14:41:04 +00:00
Bernardo Damele
1384b8794f
add parsed error messages to console_output for better debugging of failed regression test cases
2013-02-12 13:48:11 +00:00
Miroslav Stampar
6a98d375b1
More general except
2013-02-12 14:39:21 +01:00
Miroslav Stampar
212e92ea01
Minor update regarding --load-cookies (warning about expired ones)
2013-02-12 14:29:56 +01:00
Miroslav Stampar
c9447fbbe7
Minor patch to return False if --is-dba returns None
2013-02-12 13:04:42 +01:00
Miroslav Stampar
c67b39d14d
Update for a last update
2013-02-12 12:58:15 +01:00
Miroslav Stampar
72984a578d
Update for --load-cookies
2013-02-12 12:42:12 +01:00
Miroslav Stampar
c2672e78fc
Support for multiple injection marks inside the same header value (Issue #48 )
2013-02-12 12:06:13 +01:00
Bernardo Damele
b9cc127ead
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-12 09:28:28 +00:00
Bernardo Damele
70230f3513
minor fix
2013-02-12 09:28:15 +00:00
Miroslav Stampar
c75560ba69
Minor bug fix (getting ? in < 0xf char cases)
2013-02-11 21:16:35 +01:00
Miroslav Stampar
093a93938c
Bug fix (making non-query statements available for stacked conditional-error blind cases too)
2013-02-11 20:43:12 +01:00
Bernardo Damele
3786541681
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-11 18:08:04 +00:00
Bernardo Damele
8bfee3b802
started to work on #373 to improve usability when user is not DBA
2013-02-11 18:07:58 +00:00
Bernardo Damele
d6db83fe88
Send an email also when regression test is successful
2013-02-11 18:07:15 +00:00
Miroslav Stampar
6d802867fc
Bug fix (in some cases if random values are parsable as MMDD they will result as valid non-NULL TIMESTAMPADD value back - e.g. values 1224,0101,0212)
2013-02-11 12:02:03 +01:00
Miroslav Stampar
7c06a937e5
Minor refactoring
2013-02-09 20:21:17 +01:00
Bernardo Damele
f970b4f240
minor adjustment fixing the regression test stall
2013-02-09 12:19:21 +00:00
Bernardo Damele
e48181e28d
another attempt to fix the stall during regression test
2013-02-09 12:16:56 +00:00
Bernardo Damele
138a846cf1
possible fix for regression test stall
2013-02-09 10:50:06 +00:00
Bernardo Damele
1596b9ed59
revert
2013-02-08 16:43:49 +00:00
Bernardo Damele
98864e425f
minor "fix"
2013-02-08 16:30:34 +00:00
Bernardo Damele
8b510c55fb
minor code cleanup
2013-02-08 16:29:16 +00:00
Miroslav Stampar
5aaf7f1aa6
BUG fix
2013-02-08 16:44:30 +01:00
Miroslav Stampar
c0e59d94a9
Better naming
2013-02-08 16:28:58 +01:00
Miroslav Stampar
cdfe43560b
Update for an Issue #207 (and a potential patch for regression tests)
2013-02-08 16:20:48 +01:00
Miroslav Stampar
ee1017a5a7
Minor fix
2013-02-08 13:46:39 +01:00
Bernardo Damele
5324018c7e
minor typo fix
2013-02-07 14:28:39 +00:00
Bernardo Damele
c8d1020a13
re-enabled brute-force test cases
2013-02-07 14:19:58 +00:00
Bernardo Damele
d015bf98fc
renamed variable to avoid confusion
2013-02-07 14:19:07 +00:00
Bernardo Damele
07fe6d44fb
unnecessary condition here
2013-02-07 14:18:52 +00:00
Bernardo Damele
13b424a63c
important bug fix and minor code restyling
2013-02-07 14:05:57 +00:00
Bernardo Damele
b477c56b52
first steps to allow multiple scans on the same taskid - issue #297
2013-02-07 00:05:26 +00:00
Bernardo Damele
dd6c73ea24
fixed --passwords output for API - #297
2013-02-06 21:45:51 +00:00
Bernardo Damele
21afba9571
got the partial output finally properly replaced by complete output in IPC database - #297
2013-02-06 21:32:26 +00:00
Bernardo Damele
5c8335876f
minor bug fix to make --disable-coloring work on log messages too
2013-02-06 21:04:54 +00:00
Bernardo Damele
2fa2f30d21
slighlty better, still not optimal
2013-02-06 17:45:52 +00:00
Bernardo Damele
477c66ac4b
minor refactoring and trivial bug fix
2013-02-06 17:45:25 +00:00
Bernardo Damele
e439c3d3f5
minor refactoring - #297
2013-02-06 17:09:43 +00:00
Bernardo Damele
b272b0574d
minor fix to reset partRun value - #297
2013-02-06 17:09:28 +00:00
Miroslav Stampar
a367dca653
Adding a small comment
2013-02-06 10:32:19 +01:00
Miroslav Stampar
39473967aa
Minor fix
2013-02-06 10:30:54 +01:00
Miroslav Stampar
060eac110a
Cleaner version checking
2013-02-06 10:28:17 +01:00
Miroslav Stampar
b1f31103f9
Removing that ugly disk I/O error in live testing mode
2013-02-05 17:04:42 +01:00
Miroslav Stampar
934808f53b
Fix for an Issue #379
2013-02-05 16:13:45 +01:00
Bernardo Damele
e03010f48b
got rid of unnecessary output for API - #297
2013-02-05 15:00:06 +00:00
Bernardo Damele
4428ad5345
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-05 14:43:14 +00:00
Bernardo Damele
f7d826fee1
first case where partial output is retrievable via RESTful API - issue #297
2013-02-05 14:43:03 +00:00
Miroslav Stampar
01219219fc
Minor bug fix (for --first/--last through problematic DBMSes)
2013-02-05 15:03:55 +01:00
Miroslav Stampar
31daefc7c9
Minor fix (skipping one uneccesary request in single-threaded --first/--last mode)
2013-02-05 13:51:35 +01:00
Miroslav Stampar
2f69a94bcf
Bug fix for --search -C
2013-02-05 12:24:57 +01:00
Miroslav Stampar
62772125e3
Bug fix for HTTPSCertAuthHandler
2013-02-05 12:16:06 +01:00
Miroslav Stampar
c0888e92c8
Minor update
2013-02-05 12:02:48 +01:00
Miroslav Stampar
353c1cb63b
Bug fix for escaping in SQLite 3
2013-02-05 11:58:11 +01:00
Miroslav Stampar
e836629215
Bug fixes for search (safeStringFormat should not replace all if given scalar values)
2013-02-05 11:37:49 +01:00
Miroslav Stampar
31230c5a42
Minor fix
2013-02-05 11:23:22 +01:00
Miroslav Stampar
87ad96bf01
Minor cosmetic fix
2013-02-05 11:18:46 +01:00
Miroslav Stampar
7ba0da66b1
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-05 11:10:31 +01:00
Miroslav Stampar
9434cc26d8
Minor fix
2013-02-05 11:10:21 +01:00
Bernardo Damele
d0444cde3c
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-05 09:58:45 +00:00
Bernardo Damele
9da6f8e08a
more verbose parsing rule
2013-02-05 09:58:11 +00:00
Miroslav Stampar
1618086027
Minor fix
2013-02-05 10:58:02 +01:00
Miroslav Stampar
9296bdd959
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-05 10:27:43 +01:00
Miroslav Stampar
4faa5f0f49
Fix for stalling in retrieving international letters (--technique=B)
2013-02-05 10:27:31 +01:00
Bernardo Damele
9d04ae5db5
minor improvement to temporary folder name
2013-02-05 09:11:38 +00:00
Bernardo Damele
6a83eea587
added SQLite 3 test cases
2013-02-05 09:11:20 +00:00
Miroslav Stampar
fd9e1cd2c5
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-05 10:05:10 +01:00
Miroslav Stampar
44579120b5
Cosmetics
2013-02-05 10:02:11 +01:00
Bernardo Damele
3b88932dc0
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-04 23:31:51 +00:00
Bernardo Damele
0f4f808be4
minor improvement
2013-02-04 23:26:17 +00:00
Miroslav Stampar
74e82b2b53
Removing redundant check
2013-02-04 20:42:28 +01:00
Miroslav Stampar
cf8e5d535d
Minor cleanup
2013-02-04 20:15:44 +01:00
Miroslav Stampar
c5ae967fe0
Potential fix for an Issue #379
2013-02-04 17:43:58 +01:00
Miroslav Stampar
6cab3d4759
Minor update
2013-02-04 16:46:08 +01:00
Miroslav Stampar
4f2981f163
Minor fix
2013-02-04 16:37:54 +01:00
Miroslav Stampar
f4b8a3c1d8
Bug fix for boolean (multithreaded Ctrl+C) resumed values
2013-02-04 15:49:29 +01:00
Miroslav Stampar
5e4e863986
Bug fix (introduced with f1ab887c55)
2013-02-04 15:31:28 +01:00
Miroslav Stampar
235153ab39
Removal of unused imports
2013-02-04 15:29:13 +01:00
Miroslav Stampar
7e1ff1bb8e
Same refactoring as the last commit
2013-02-04 15:26:44 +01:00
Miroslav Stampar
0cc6e68be2
Refactoring MySQL fingeprint.py (those payloads are now stored into session file too)
2013-02-04 15:12:03 +01:00
Bernardo Damele
5a8f94a1e1
temporary patch
2013-02-04 09:15:05 +00:00
Bernardo Damele
9370f96a67
step by step getting there to partial output presentation to restful API (issue #297 ), not quite yet though..
2013-02-03 22:09:33 +00:00
Bernardo Damele
b55555e4e5
minor bug fix
2013-02-03 21:39:26 +00:00
Bernardo Damele
dc2bbbeaa7
minor revert
2013-02-03 20:55:58 +00:00
Bernardo Damele
df3cc38cd9
minor improvements
2013-02-03 15:39:07 +00:00
Bernardo Damele
4c13e0e5a1
minor mandatory fix for git pull to work
2013-02-03 11:34:32 +00:00
Bernardo Damele
b63144d90b
leftover
2013-02-03 11:32:07 +00:00
Bernardo Damele
bd1ea13b8d
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-02-03 11:31:12 +00:00
Bernardo Damele
f8bc74758c
improvement to restful API to store to IPC database partial entries, not yet functional (issue #297 )
2013-02-03 11:31:05 +00:00
Bernardo Damele
a92f1fb3b4
minor update
2013-02-03 11:29:57 +00:00
Miroslav Stampar
e7b93b5b66
Implementation for an Issue #363
2013-02-01 17:24:04 +01:00
Miroslav Stampar
231ea51fe6
Removing leftover
2013-02-01 17:10:40 +01:00
Miroslav Stampar
993372aae4
Bug fix (causing search problems)
2013-02-01 11:24:17 +01:00
Miroslav Stampar
6d942f92b5
Removing --check-payload (PHPIDS doesn't update rules lately; also, WAF/IDS/IPS is more than just regexes (unencoding, removing junk, etc.))
2013-02-01 10:03:06 +01:00
Miroslav Stampar
68e507ea9f
Update for an SQLite3 time-based (heavy query) payloads (better timedelay)
2013-01-31 18:59:18 +01:00
Miroslav Stampar
81d4f9f7d1
Bug fix for last regression test (--search related)
2013-01-31 16:41:23 +01:00
Miroslav Stampar
8d51b4b63a
Minor bug fix
2013-01-31 16:24:44 +01:00
Miroslav Stampar
d6606a8f31
Patch to prevent problems like Issue #381
2013-01-31 13:58:39 +01:00
Miroslav Stampar
cfcf8a3abb
Another update for an Issue #380 (--common-... switches)
2013-01-31 13:49:19 +01:00
Miroslav Stampar
f5844eabae
Valuable data is potentially lost if page not parsed in dump mode (e.g. --technique=B and error occuring) <- partial revert of previous optimization commit 10bdd90e60
2013-01-31 13:32:14 +01:00
Miroslav Stampar
410f6ad476
Fix for an Issue #380
2013-01-31 13:26:38 +01:00
Miroslav Stampar
2420a4b626
Update for an Issue #342 and #372
2013-01-31 10:01:52 +01:00
Miroslav Stampar
9b4eaa9272
Minor fix
2013-01-30 18:21:15 +01:00
Miroslav Stampar
6b6e36b2ec
Continuation of work on fixing DISTINCT/--search issues (Oracle)
2013-01-30 18:08:34 +01:00
Miroslav Stampar
838e98192e
Consistency update (we are not using DISTINCT in inband counterparts too)
2013-01-30 17:25:36 +01:00
Miroslav Stampar
112ff952d4
Continuation of cleaning up a mess in Oracle's world of DISTINCT (part of Issue #342 and #372 )
2013-01-30 17:08:17 +01:00
Miroslav Stampar
fdea8ddea6
Starting to clean up a mess in Oracle's world of DISTINCT (part of Issue #342 and #372 )
2013-01-30 16:55:09 +01:00
Miroslav Stampar
93c59c7277
Fix for a --privileges --technique=B --dbms=Oracle (when one user has no privileges everything is foobared)
2013-01-30 16:41:57 +01:00
Bernardo Damele
103045d284
variable renamed
2013-01-30 15:30:34 +00:00
Miroslav Stampar
95998e3989
Implementing undocumented way how to retrieve w+ temporary directory name on MsSQL (suggested by Vlado Velichkovski)
2013-01-30 14:38:21 +01:00
Miroslav Stampar
742c66fad2
Adding one more test (switch --hex)
2013-01-30 11:40:12 +01:00
Miroslav Stampar
f33bf06c88
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-30 11:38:20 +01:00
Miroslav Stampar
6005046280
Bug fix (--dbms=mysql --tables -D testdb --exclude-sysdbs --technique=E was not working)
2013-01-30 11:36:04 +01:00
Bernardo Damele
6dfe91165d
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-30 10:34:51 +00:00
Bernardo Damele
8519717f25
minor fixes to --live-test
2013-01-30 10:32:56 +00:00
Miroslav Stampar
f391937083
Minor refactoring
2013-01-30 10:43:46 +01:00
Miroslav Stampar
d6fb0e8545
Update for an Issue #352
2013-01-30 10:38:11 +01:00
Miroslav Stampar
bd08ede117
Minor fine tuning
2013-01-29 21:06:02 +01:00
Miroslav Stampar
f41460f8d8
Better naming
2013-01-29 20:53:11 +01:00
Miroslav Stampar
95b922309c
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-29 20:50:40 +01:00
Bernardo Damele
e8bd3c9c9f
cosmetics
2013-01-29 17:00:28 +00:00
Bernardo Damele
1907c7c83a
fixed stall
2013-01-29 16:39:14 +00:00
Bernardo Damele
8912436c68
tentative fix for stall
2013-01-29 16:30:59 +00:00
Bernardo Damele
8f36f92dd3
minor fix
2013-01-29 16:23:30 +00:00
Bernardo Damele
1ed2b0e5da
missing mandatory update before regression test
2013-01-29 16:13:10 +00:00
Bernardo Damele
edd6699ed1
code refactoring and added /status method for scan (issue #297 )
2013-01-29 16:11:25 +00:00
Bernardo Damele
c47b44e93f
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-29 15:38:16 +00:00
Bernardo Damele
1152cf8958
increased SQLite connection timeout to 3 seconds, the object will now wait for the lock to go away max 3 seconds, no longer 1 only. Relevant code refactoring and minor improvements all over the API library (issue #297 )
2013-01-29 15:38:09 +00:00
Bernardo Damele
9677e0f910
more data content types for API (issue #297 )
2013-01-29 15:36:19 +00:00
Bernardo Damele
92ae8145df
ignore any non-relevant string: avoid storing to the API, careful this can introduce bugs but it is necessary at this stage of development (issue #297 )
2013-01-29 15:35:51 +00:00
Bernardo Damele
a56f4ec15c
techniques has to go too to the API (issue #297 )
2013-01-29 15:34:53 +00:00
Bernardo Damele
bfce7210e6
improvements to the dump library to output to the API data fetched properly formatted (issue #297 )
2013-01-29 15:34:20 +00:00
Bernardo Damele
eeecb3fe2c
split init() into two separate functions for API purposes (issue #297 )
2013-01-29 15:33:16 +00:00
Miroslav Stampar
a59ac8e27f
Trivial cosmetics
2013-01-29 16:30:38 +01:00
Miroslav Stampar
55a9f91bbf
Refactoring between.py script
2013-01-29 16:22:19 +01:00
Miroslav Stampar
f2512d06db
Removing unneeded whitespace in inference queries
2013-01-29 16:13:49 +01:00
Miroslav Stampar
f4b7b3fd35
Minor cosmetics
2013-01-29 16:04:20 +01:00
Miroslav Stampar
9eca41bae2
Minor fix
2013-01-29 15:55:50 +01:00
Miroslav Stampar
a104de01d7
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-29 15:35:01 +01:00
Miroslav Stampar
7e73825ece
Minor cosmetics
2013-01-29 15:34:41 +01:00
Bernardo Damele
085495024f
minor adjustment
2013-01-29 01:44:57 +00:00
Bernardo Damele
f1ab887c55
major enhancement, code refactoring for issue #297
2013-01-29 01:39:27 +00:00
Bernardo Damele
d07881b6c3
apply a little bit of secure coding practices to the API
2013-01-27 12:26:40 +00:00
Bernardo Damele
4d95573e6c
cosmetics
2013-01-27 12:01:50 +00:00
Bernardo Damele
61eb16274e
more appropriate log file name
2013-01-26 16:24:27 +00:00
Bernardo Damele
a5ce0c9a04
leftover
2013-01-26 16:23:39 +00:00
Bernardo Damele
39c84ffabe
missing import
2013-01-26 16:11:27 +00:00
Bernardo Damele
234e4c9f69
consolidated into one script
2013-01-26 16:11:09 +00:00
Bernardo Damele
2a9fe62c3f
bind payload is preferred if filtering does not allow reverse connection
2013-01-26 15:51:47 +00:00
Bernardo Damele
cd4075f6a3
no raise, just pass at ctrl-c
2013-01-26 15:33:09 +00:00
Bernardo Damele
a0b9e0f1c5
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-25 17:11:38 +00:00
Bernardo Damele
195d17449e
first test of stdout/stderr redirect to a database when sqlmap is executed from restful API ( #297 )
2013-01-25 17:11:31 +00:00
Miroslav Stampar
c06f94e2c8
Fix for an Issue #378
2013-01-25 16:38:41 +01:00
Miroslav Stampar
f9b44d6ff7
Adding test cases for using custom injection marks
2013-01-25 16:07:27 +01:00
Miroslav Stampar
8c84a16cb7
Minor style update for an Issue #377
2013-01-25 12:52:31 +01:00
Miroslav Stampar
479f791112
Minor fix
2013-01-25 12:41:51 +01:00
Miroslav Stampar
194a9e7b88
Implementation for an Issue #377
2013-01-25 12:34:57 +01:00
Miroslav Stampar
e150316d97
Slight update for a greatest.py (more general approach)
2013-01-25 10:37:45 +01:00
Miroslav Stampar
ac6c9a808a
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-25 10:29:36 +01:00
Miroslav Stampar
90daef0b9c
Update of a doc/THANKS
2013-01-25 10:27:57 +01:00
Bernardo Damele
aed833c1d2
fixed test case
2013-01-24 14:59:55 +00:00
Miroslav Stampar
adfb862cd5
Trivial style update
2013-01-24 15:12:52 +01:00
Bernardo Damele
5b3c8d8991
first implementation of asynchronous inter-protocol communication between the sqlmap RESTful API and the sqlmap engine with SQLite
2013-01-24 12:57:24 +00:00
Bernardo Damele
7d01eb79b4
minor fix
2013-01-24 00:55:45 +00:00
Miroslav Stampar
2f4cf61271
Merge pull request #375 from frohoff/fix_non_ascii_header_name
...
fixed response header logging for header names with special chars
2013-01-23 11:56:51 -08:00
Chris Frohoff
218a6a9695
fixed response header logging for header names with special chars
2013-01-23 11:10:25 -08:00
Bernardo Damele
3c0c7f776f
minor fix
2013-01-23 16:57:51 +00:00
Bernardo Damele
f848f259a6
upper() -D value for certain DBMSes
2013-01-23 16:22:28 +00:00
Bernardo Damele
f1534a178a
regexp fixes
2013-01-23 16:22:01 +00:00
Bernardo Damele
9ceb4839ac
added test cases for --common-tables across all DBMSes and supported techniques
2013-01-23 15:54:58 +00:00
Bernardo Damele
012815333c
minor bug fix to ignore provided -D when brute-forcing columns/tables names and the DBMS is either Access, Firebird or SQLite
2013-01-23 15:52:03 +00:00
Miroslav Stampar
c83f468a37
Trivial changes
2013-01-23 15:34:20 +01:00
Miroslav Stampar
35d76f3da5
Adding missing stuff related to the last commit
2013-01-23 14:48:31 +01:00
Miroslav Stampar
9825e247db
Refactoring search module
2013-01-23 14:22:35 +01:00
Bernardo Damele
599ad74a32
typo fix
2013-01-23 13:05:10 +00:00
Bernardo Damele
a3c779839a
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-23 13:02:14 +00:00
Bernardo Damele
ff160abf10
minor bug fix
2013-01-23 13:02:02 +00:00
Bernardo Damele
45af22872a
fixes #370 (the bug was introduced with commit edb977a74e)#
2013-01-23 13:00:58 +00:00
Miroslav Stampar
232f8d3585
Fix for an Issue #368
2013-01-23 13:36:17 +01:00
Bernardo Damele
7ee07d031a
added PostgreSQL stacked queries test case
2013-01-23 12:15:20 +00:00
Bernardo Damele
314ed22fc3
added preventive cleanup test case
2013-01-23 12:12:30 +00:00
Bernardo Damele
f4028bd7d2
minor adjustment
2013-01-23 02:10:38 +00:00
Bernardo Damele
d8a0e7eacb
fixes #187
2013-01-23 01:27:01 +00:00
Bernardo Damele
f3ff239e62
minor fix
2013-01-23 00:21:11 +00:00
Bernardo Damele
aafc5b5623
added one just in case test case to check if all params are tested as they should be
2013-01-23 00:18:54 +00:00
Bernardo Damele
2f1c174879
minor bug fix
2013-01-23 00:18:29 +00:00
Bernardo Damele
5635776173
proper SQLite 2 library
2013-01-22 18:56:25 +00:00
Bernardo Damele
91c00939f7
added one more test case
2013-01-22 18:28:59 +00:00
Bernardo Damele
dea15b5892
notify user if --udf-inject is provided but no stacked queries SQLi is detected
2013-01-22 18:28:48 +00:00
Miroslav Stampar
d6a361f859
Proper implementation for --technique=Q --dbms=Firebird
2013-01-22 16:31:26 +01:00
Miroslav Stampar
719c7f622b
Probable fix for --technique=Q --dbms=Firebird (but also other potential issues with splitting of fields in expressions)
2013-01-22 15:51:06 +01:00
Miroslav Stampar
2ec828f1cb
Fix for an Issue #367
2013-01-22 14:27:17 +01:00
Miroslav Stampar
5ea45af1c4
Warming up for Issue #366 and #367
2013-01-22 14:14:20 +01:00
Miroslav Stampar
09c02c6c72
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-22 14:08:31 +01:00
Miroslav Stampar
15b0ab1b44
Fix for a 'no parameter found' problem when user says N on 'custom injection mark found in POST...'
2013-01-22 14:08:19 +01:00
Bernardo Damele
4f081a6a9b
typo fixes
2013-01-22 13:00:15 +00:00
Bernardo Damele
afa9046e74
added Firebird custom enumeration test cases and stricten a few cases to make sure query length calculation function works properly with multi-threading/boolean technique
2013-01-22 12:34:11 +00:00
Bernardo Damele
061aef57ba
missing import
2013-01-22 11:25:01 +00:00
Bernardo Damele
29a65b5cdc
added Firebird search test cases
2013-01-22 11:23:48 +00:00
Miroslav Stampar
59b02539ca
More general approach regarding that last commit
2013-01-22 11:34:34 +01:00
Miroslav Stampar
01f1488f07
Minor patch (annoying trailing spaces for some DBMSes --technique=B --sql-query)
2013-01-22 11:29:51 +01:00
Miroslav Stampar
b8318efecc
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-22 11:29:15 +01:00
Bernardo Damele
bd7fd862b0
forgot import
2013-01-22 10:16:18 +00:00
Bernardo Damele
edb977a74e
bug fix so that if search fails with union/error and blind techniques are available, it falls back to them (like any other enumeration switch) and minor bug fix so that in search mode, the provided table name to search is upped
2013-01-22 10:14:35 +00:00
Bernardo Damele
11413a0f03
added Firebird search test cases
2013-01-22 10:04:17 +00:00
Bernardo Damele
e23340f002
added support for search for tables on Firebird (issue #365 )
2013-01-22 09:53:05 +00:00
Bernardo Damele
d2ff9bccbb
minor adjustment
2013-01-21 21:00:03 +00:00
Bernardo Damele
bc5a7e49e9
done with DB2 test cases (issue #312 )
2013-01-21 20:53:11 +00:00
Bernardo Damele
f3cead1729
cosmetics
2013-01-21 20:05:25 +00:00
Bernardo Damele
e9dea8d394
no need to raise an exception if one enumeration fails
2013-01-21 17:11:46 +00:00
Bernardo Damele
e558040810
minor fix to previous commit
2013-01-21 17:10:56 +00:00
Bernardo Damele
d43b04c582
better detection if vulnerable of not for regression test
2013-01-21 17:09:35 +00:00
Bernardo Damele
3cfa6cd191
minor adjustments
2013-01-21 16:41:47 +00:00
Bernardo Damele
d5de5306d6
minor fixes following recent enhancements
2013-01-21 16:38:31 +00:00
Miroslav Stampar
472f5e35c2
Removing that space char
2013-01-21 17:35:23 +01:00
Miroslav Stampar
5d318b4980
Fix for a ISNULL mechanism in Firebird
2013-01-21 17:33:09 +01:00
Miroslav Stampar
f9d330ec98
Fix for that Firebird column data types issue (tec=EU)
2013-01-21 17:20:46 +01:00
Miroslav Stampar
99bc4a9005
Generic approach for dealing with that nasty Firebird habit of appending spaces to (tec=EU) varchar casted values
2013-01-21 17:17:20 +01:00
Miroslav Stampar
b35a0810ef
Fix for an Issue #364
2013-01-21 17:01:52 +01:00
Miroslav Stampar
457217f2d3
Fix for an Issue #356
2013-01-21 16:46:48 +01:00
Miroslav Stampar
1e3f68c7ff
Rewriting some query crafting parts (especially those .find(' FROM '))
2013-01-21 16:15:38 +01:00
Miroslav Stampar
832d95984c
IFNULL-like mechanism now works on SQLite 2 too
2013-01-21 15:04:27 +01:00
Miroslav Stampar
75bf8528d1
Minor just in case update
2013-01-21 14:50:43 +01:00
Miroslav Stampar
c55a002f95
Language fix
2013-01-21 13:19:08 +01:00
Miroslav Stampar
80255433b0
Trivial style update
2013-01-21 13:18:34 +01:00
Miroslav Stampar
af0db14963
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-21 13:10:36 +01:00
Miroslav Stampar
0e86175342
Adding new common function for further refactoring
2013-01-21 11:50:47 +01:00
Bernardo Damele
e751556e9b
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-21 10:30:54 +00:00
Bernardo Damele
eb68da96d6
stylistic update
2013-01-21 10:30:49 +00:00
Miroslav Stampar
65c55a6a49
Fix for escaping single quote character(s)
2013-01-21 11:21:41 +01:00
Miroslav Stampar
3200134b3b
Fix for a regression test #30 test case fail (Firebird inline)
2013-01-21 10:12:54 +01:00
Miroslav Stampar
aebf2c1350
Slightly better payload for Firebird delay-based SQLi (adding sligtly more delay)
2013-01-20 23:10:58 +01:00
Miroslav Stampar
069c6acabd
Another update for an Issue #362
2013-01-20 22:47:26 +01:00
Miroslav Stampar
8f955b6364
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-20 22:16:47 +01:00
Miroslav Stampar
a7028af2e9
Patch for an Issue #362 (more work required)
2013-01-20 22:16:34 +01:00
Bernardo Damele
fefad3cba1
stylistic improvements
2013-01-20 17:40:15 +00:00
Miroslav Stampar
b4a55a809e
Refactoring DBMS string escaping functions
2013-01-20 13:45:58 +01:00
Bernardo Damele
3b57fe2924
add test case number to email
2013-01-20 11:43:00 +00:00
Bernardo Damele
3373e30808
minor fix for a bug introduced with commit 1ad9e26a21
2013-01-20 02:40:40 +00:00
Bernardo Damele
845ec006d7
fixed again
2013-01-20 01:33:22 +00:00
Bernardo Damele
115be9d7b5
minor fixes
2013-01-20 01:26:46 +00:00
Bernardo Damele
6f61fc04f1
minor bug fix
2013-01-20 01:22:25 +00:00
Bernardo Damele
d46234e30c
minor fix
2013-01-20 01:07:00 +00:00
Bernardo Damele
7aa3338bd4
add start and end times to log
2013-01-19 18:33:09 +00:00
Bernardo Damele
ac545548b3
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-19 18:28:30 +00:00
Bernardo Damele
bedfe1ba1f
syntax fix
2013-01-19 18:28:24 +00:00
Miroslav Stampar
0a4f5d2e51
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-19 19:08:18 +01:00
Miroslav Stampar
e9641e30db
This last commit was in haste :)
2013-01-19 19:07:38 +01:00
Miroslav Stampar
6a87dd9225
Minor update (just for consistency with the rest of code)
2013-01-19 19:07:06 +01:00
Miroslav Stampar
979e108c87
Minor update (just for consistency with the rest of code)
2013-01-19 19:06:51 +01:00
Bernardo Damele
f89b25fdb6
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-19 18:04:38 +00:00
Bernardo Damele
adf97e630f
add possibility to provide a list of web server document root possible directories for web shell upload in --os-cmd and --os-shell for MySQL
2013-01-19 18:04:33 +00:00
Miroslav Stampar
9ce2395405
Minor refactoring
2013-01-19 18:40:44 +01:00
Miroslav Stampar
3f4c010370
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-19 18:28:52 +01:00
Miroslav Stampar
efe26ac3f8
In case that content-length header was not in a desired case ('Content-length') POST request file would fail badly (repeating original content-length header value)
2013-01-19 18:28:37 +01:00
Bernardo Damele
6a62292a3f
layout adjustment
2013-01-19 17:11:16 +00:00
Miroslav Stampar
bb6b89fe93
Patch for an Issue #360
2013-01-19 18:06:36 +01:00
Bernardo Damele
dcf2dcd03d
all we need to debug failed test cases while regression test run..
2013-01-19 17:04:57 +00:00
Bernardo Damele
f22fd396ef
write the test case name before it is run so if the test case crashes badly, we can trace back what test case it was at a later stage
2013-01-19 16:41:19 +00:00
Bernardo Damele
47f0d89fc5
sqlmap.org mail server rejects the email, hence use Gmail
2013-01-19 16:26:22 +00:00
Bernardo Damele
640e0eecc6
improved cron script to report any malfunction by email
2013-01-19 16:25:41 +00:00
Bernardo Damele
a24eaffacc
fixed --columns on DB2, inline with Oracle and other DBMSes now
2013-01-19 16:14:25 +00:00
Bernardo Damele
ab607bd378
minor bug fix to verify test case file exists before it gets read
2013-01-19 16:07:30 +00:00
Bernardo Damele
1923ef691e
just in case, add also the test case name inside the temp folder for debug purposes
2013-01-19 16:06:46 +00:00
Bernardo Damele
c95119559e
minor bug fix
2013-01-19 00:41:51 +00:00
Bernardo Damele
b05c6cbd13
leftover
2013-01-19 00:29:42 +00:00
Bernardo Damele
30273e03fe
leftover
2013-01-19 00:28:48 +00:00
Bernardo Damele
0e78fbef56
correctly format SQLi payload for inline query technique
2013-01-19 00:28:03 +00:00
Bernardo Damele
32a12c7e2b
handle exception reported in issue #359
2013-01-19 00:24:15 +00:00
Bernardo Damele
89ddd54a75
added Firebird inline query payload, requires some work though engine-side for the vector to be usable
2013-01-19 00:05:15 +00:00
Bernardo Damele
10d86d042c
enough..
2013-01-18 23:46:26 +00:00
Bernardo Damele
e76213ef5d
more fixes
2013-01-18 23:37:13 +00:00
Bernardo Damele
6be7eee8d6
more fixes
2013-01-18 23:35:16 +00:00
Bernardo Damele
56eaa073ce
fixed test cases for Firebird - #312
2013-01-18 23:32:39 +00:00
Bernardo Damele
edeb181c4f
added first bunch of test cases for Firebird, issue #312
2013-01-18 23:17:43 +00:00
Bernardo Damele
d1acdee9c4
fixed --count for DBMSes that are single-database
2013-01-18 23:07:16 +00:00
Bernardo Damele
8748cceff3
no point enumerating current database for --count on some DBMSes
2013-01-18 23:04:28 +00:00
Bernardo Damele
a390c48692
code refactoring
2013-01-18 23:04:01 +00:00
Bernardo Damele
a4b0b98f8f
aligned Firebird to recent DB2 string escaping syntax fix
2013-01-18 22:57:57 +00:00
Bernardo Damele
4526e31485
bug fix for Firebird fingerprint (issue #357 )
2013-01-18 22:32:58 +00:00
Bernardo Damele
b176cdb578
layout adjustment
2013-01-18 22:10:52 +00:00
Bernardo Damele
1f4c6a8371
avoid blank line if password hashes have not been fetched
2013-01-18 22:10:36 +00:00
Bernardo Damele
b80e195c78
bug fix for #355
2013-01-18 22:10:10 +00:00
Bernardo Damele
2471f325b2
minor adjustments
2013-01-18 21:47:25 +00:00
Bernardo Damele
1ad9e26a21
bug fix for ORDER BY users provided statements (issue #354 )
2013-01-18 21:40:50 +00:00
Bernardo Damele
ebd1d3095b
done with test cases for Oracle - issue #312
2013-01-18 21:40:11 +00:00
Bernardo Damele
d594978857
typo fix again
2013-01-18 20:48:37 +00:00
Bernardo Damele
bab9485561
typo fix
2013-01-18 20:48:08 +00:00
Bernardo Damele
f3d7be9200
more adjustments for #353
2013-01-18 20:44:56 +00:00
Bernardo Damele
2550bbc05e
fix for #353
2013-01-18 20:40:38 +00:00
Bernardo Damele
2463e51e73
added one more test case for DB2 and a few search-related cases for Oracle (issue #312 )
2013-01-18 20:37:20 +00:00
Miroslav Stampar
11e27f07e0
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-18 17:00:20 +01:00
Miroslav Stampar
ac7709204a
Better fix for that page/headers/comparison --string candidate problem
2013-01-18 17:00:11 +01:00
Miroslav Stampar
8141d17985
Revert of previous commit (more care has to be done regarding headers dynamicity)
2013-01-18 16:49:35 +01:00
Bernardo Damele
6cd780ecc0
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-18 15:36:32 +00:00
Bernardo Damele
7c7b608b95
more adjustments
2013-01-18 15:36:22 +00:00
Miroslav Stampar
33094a118c
Fix for an Issue where '--string' is being automatically picked not looking properly in headers too
2013-01-18 16:35:09 +01:00
Bernardo Damele
c61ee5e5ef
more adjustments
2013-01-18 15:34:14 +00:00
Bernardo Damele
a73aa422fc
minor enhancements - #311
2013-01-18 15:29:21 +00:00
Bernardo Damele
0953ce5b08
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-18 15:10:57 +00:00
Bernardo Damele
f49657eacc
minor fix to previous commit
2013-01-18 15:10:34 +00:00
Miroslav Stampar
09af079c2d
Minor fix
2013-01-18 16:03:54 +01:00
Miroslav Stampar
601eb1e49a
Unescaping is renamed to escaping
2013-01-18 15:40:37 +01:00
Bernardo Damele
c717de9c9d
added regression test cron job script - issue #311
2013-01-18 14:12:00 +00:00
Bernardo Damele
a43202f3c0
updated copyright
2013-01-18 14:07:51 +00:00
Bernardo Damele
eafc0e776e
leftover
2013-01-18 13:54:16 +00:00
Bernardo Damele
fb752e6936
catch SMTP exception if any - issue #311
2013-01-18 13:46:50 +00:00
Bernardo Damele
3dd9f29938
layout adjustment
2013-01-18 13:42:48 +00:00
Bernardo Damele
75d0cee994
minor adjustments - issue #311
2013-01-18 13:36:50 +00:00
Bernardo Damele
454f2ae10b
ready for production - closes #311
2013-01-18 13:35:27 +00:00
Bernardo Damele
7ccdfc7244
minor enhancements - issue #311
2013-01-18 13:33:05 +00:00
Bernardo Damele
50d7386012
minor fix - issue #311
2013-01-18 13:27:47 +00:00
Bernardo Damele
7c101d9dfc
minor fix - issue #311
2013-01-18 13:25:54 +00:00
Bernardo Damele
c8b1013c42
minor fix - issue #311
2013-01-18 13:20:19 +00:00
Bernardo Damele
13b776fb9f
minor fix
2013-01-18 13:10:26 +00:00
Bernardo Damele
5375c705a0
minor fix
2013-01-18 13:09:50 +00:00
Bernardo Damele
27d9d42bd6
minor adjustments - issue #311
2013-01-18 13:05:24 +00:00
Bernardo Damele
1bb061f68c
improvements to --live-test
2013-01-18 13:02:35 +00:00
Bernardo Damele
b3d9f1a907
more impovements, issue #311
2013-01-18 13:02:23 +00:00
Bernardo Damele
738ccb643d
minor output adjustment
2013-01-18 11:41:09 +00:00
Bernardo Damele
9354ec688e
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-18 11:04:04 +00:00
Bernardo Damele
de26a31493
more enhancements - issue #311
2013-01-18 11:04:00 +00:00
Miroslav Stampar
33ea811c6c
Removing some unused stuff (mainly imports)
2013-01-18 11:50:02 +01:00
Bernardo Damele
a7cab63796
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-18 10:44:43 +00:00
Bernardo Damele
dcec56e002
first implementation of automated regression test script (issue #311 )
2013-01-18 10:44:38 +00:00
Miroslav Stampar
aa467cb54c
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-18 11:31:25 +01:00
Miroslav Stampar
17d36684b5
Removing obsolete proxy handling code (Python < 2.6)
2013-01-18 11:30:52 +01:00
Miroslav Stampar
e7576a3b11
Better naming
2013-01-18 11:21:23 +01:00
Miroslav Stampar
4d5bae7131
Removing some obsolete functions
2013-01-18 11:18:56 +01:00
Miroslav Stampar
bcc907ce09
Minor update
2013-01-18 11:00:21 +01:00
Miroslav Stampar
d1008b45b5
Minor removal of unused function
2013-01-18 10:46:06 +01:00
Miroslav Stampar
caae773b2d
Minor removal of redundant code
2013-01-18 10:44:57 +01:00
Bernardo Damele
d66f7e22b1
more fixes to test cases
2013-01-18 09:32:05 +00:00
Bernardo Damele
a92ae93847
minor bug fix to properly identify if user is admin on Oracle across all techniques
2013-01-18 09:22:53 +00:00
Miroslav Stampar
1599b5e37f
Fix for an Issue #351
2013-01-18 10:20:45 +01:00
Miroslav Stampar
b0a13be985
Just a little refactoring
2013-01-18 10:12:45 +01:00
Bernardo Damele
e4ee4f9557
fixed some test cases
2013-01-17 23:17:33 +00:00
Bernardo Damele
ce263b794f
on DB2 there are no users password hashes to dump
2013-01-17 22:17:55 +00:00
Bernardo Damele
d1b91790f5
fixed --count on DB2
2013-01-17 22:13:59 +00:00
Bernardo Damele
5225375048
proper fix
2013-01-17 22:04:21 +00:00
Bernardo Damele
d2d3878de1
typo fix
2013-01-17 21:58:53 +00:00
Bernardo Damele
b231e52980
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-17 21:58:23 +00:00
Bernardo Damele
a5e9168993
minor fix because boolean-based blind on DB2 is a little bit different from other DBMSes
2013-01-17 21:58:15 +00:00
Miroslav Stampar
e941e60b20
Minor just in place update for an Issue #348
2013-01-17 22:44:55 +01:00
Bernardo Damele
1d6e642d41
fixed url
2013-01-17 21:29:00 +00:00
Bernardo Damele
38eb4eb33e
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-17 21:03:11 +00:00
Bernardo Damele
b6e44ae64e
fix for #349 (compatible with all others DBMSes too)
2013-01-17 21:03:03 +00:00
Miroslav Stampar
a8e3fd58c5
Implementation for an Issue #348
2013-01-17 21:49:58 +01:00
Miroslav Stampar
081e7a3b96
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-17 21:49:41 +01:00
Bernardo Damele
acac8c359b
fixed --current-db query for IBM DB2
2013-01-17 20:47:35 +00:00
Miroslav Stampar
8480ceddcb
Minor style update
2013-01-17 19:55:56 +01:00
Miroslav Stampar
507f185b69
Revert of patch for an Issue #347
2013-01-17 18:38:37 +01:00
Miroslav Stampar
9dd69042de
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-17 15:31:55 +01:00
Miroslav Stampar
f7eda07d92
Patch for an Issue #347
2013-01-17 15:30:14 +01:00
Bernardo Damele
5e059ab6db
added check for DB2 lib
2013-01-17 14:20:34 +00:00
Miroslav Stampar
a38b3e397c
Patch for an Issue #286
2013-01-17 14:17:39 +01:00
Miroslav Stampar
65273295e3
Implementing a check for an Issue #25
2013-01-17 13:56:04 +01:00
Miroslav Stampar
9428d1819e
Fix for an Issue #346
2013-01-17 12:03:02 +01:00
Miroslav Stampar
3ab4a5e36d
Fix for an Issue #345
2013-01-17 11:50:12 +01:00
Miroslav Stampar
51a77d1fe2
Minor update for an Issue #8
2013-01-17 11:37:45 +01:00
Miroslav Stampar
f11e9ffe40
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-17 11:34:13 +01:00
Bernardo Damele
74286e339f
test if boolean also works correctly for --os-cmd
2013-01-16 15:36:35 +00:00
Miroslav Stampar
14b7e655a9
Minor refactoring
2013-01-16 16:33:04 +01:00
Bernardo Damele
6f08d10d07
leftover
2013-01-16 15:16:18 +00:00
Bernardo Damele
8d0ab2fd43
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-16 15:14:04 +00:00
Bernardo Damele
1c8bd95e68
more work on Oracle test cases ( #312 )
2013-01-16 15:13:47 +00:00
Miroslav Stampar
053b7d12b4
Minor language update
2013-01-16 16:07:12 +01:00
Miroslav Stampar
4bdc0a8a7f
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-16 16:04:18 +01:00
Miroslav Stampar
fb7243c237
Cleaning a mess where multi-threaded HTTP requests (in log) had sometimes same UIDs
2013-01-16 16:04:00 +01:00
Bernardo Damele
f25d7ffc14
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-16 15:00:54 +00:00
Bernardo Damele
6b0ed1c581
fixed parsing reg exps to work with Oracle XE ( #312 )
2013-01-16 15:00:45 +00:00
Miroslav Stampar
c0a6e1c3a7
Finishing first usable prototype for an Issue #8
2013-01-16 14:54:37 +01:00
Miroslav Stampar
ff5ec48abd
Minor update for an Issue #8
2013-01-16 14:16:22 +01:00
Bernardo Damele
3464a70ac2
bug fix: without this generic concatenation of strings in concatQuery(), detection of UNION query SQLi only (--technique U) when the page did not disclose any DBMS error message and it was not MySQL (for which there are UNION SQLi specific payloads) was not detected
2013-01-16 01:53:33 +00:00
Bernardo Damele
542f6de72e
typo fix
2013-01-16 01:31:03 +00:00
Bernardo Damele
a3493769ca
minor fix
2013-01-16 00:45:18 +00:00
Bernardo Damele
983593510c
ported Oracle checks to express edition
2013-01-15 23:59:29 +00:00
Bernardo Damele
e16ad38d3e
more work on #342
2013-01-15 18:15:07 +00:00
Bernardo Damele
329047fc12
restored fix for #210 to keep --hex work with --technique B
2013-01-15 17:51:40 +00:00
Bernardo Damele
404ecbcaec
typo fix
2013-01-15 17:14:58 +00:00
Bernardo Damele
2a751e075d
more work on #342
2013-01-15 17:14:44 +00:00
Bernardo Damele
ec076f5f8a
write console output to temporary folder in any case the test case fails, even if no traceback is raised
2013-01-15 15:51:03 +00:00
Bernardo Damele
4eaa0d17aa
Fix in forging query to calculate query output length - closes issue #342
2013-01-15 15:50:20 +00:00
Miroslav Stampar
7a1d484115
Implementation for an Issue #340
2013-01-15 16:05:33 +01:00
Bernardo Damele
3f84cefc77
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-15 14:59:22 +00:00
Bernardo Damele
1cafe605af
added more Oracle test cases
2013-01-15 14:59:15 +00:00
Bernardo Damele
c51358953a
add more Oracle system dbs
2013-01-15 14:51:29 +00:00
Miroslav Stampar
04aa39f0c6
Minor update
2013-01-15 13:51:19 +01:00
Miroslav Stampar
02f0e72cc6
Minor update of other/corner case titles
2013-01-15 11:10:03 +01:00
Miroslav Stampar
498a576e39
Removing obsolete data
2013-01-15 10:59:46 +01:00
Miroslav Stampar
5ee653dd89
Merging commit 57bcbb458eade2850a6d7623ecddbe49c69cf334 from @morisson
2013-01-15 10:14:02 +01:00
Miroslav Stampar
461ee24dcd
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-15 10:02:46 +01:00
Bernardo Damele
3fa720e699
added first Oracle test cases
2013-01-14 17:30:42 +00:00
Bernardo Damele
8a2b994b94
added SQLite test cases (issue #312 )
2013-01-14 16:50:24 +00:00
Bernardo Damele
413b5e7ab4
fixed error message
2013-01-14 16:49:05 +00:00
Bernardo Damele
e555c2be30
added support for --search -T for SQLite
2013-01-14 16:26:11 +00:00
Bernardo Damele
8cff8301f5
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-14 16:17:53 +00:00
Bernardo Damele
48e0154fc3
added SQLite inline queries payload
2013-01-14 15:30:01 +00:00
Miroslav Stampar
2cac7e860e
Minor refactoring
2013-01-14 16:27:50 +01:00
Miroslav Stampar
31302eb707
Minor update
2013-01-14 16:26:07 +01:00
Miroslav Stampar
2a86c1cadc
Another cosmetics
2013-01-14 16:24:55 +01:00
Miroslav Stampar
1e1f560d0c
Minor cosmetics
2013-01-14 16:24:28 +01:00
Miroslav Stampar
0c2474cc22
Minor update
2013-01-14 16:21:40 +01:00
Miroslav Stampar
a5a309212a
Fix for an Issue #339
2013-01-14 16:18:03 +01:00
Bernardo Damele
e835a2af9a
minor bug fix
2013-01-14 13:43:03 +00:00
Bernardo Damele
3e2c3851f3
Make --live-test Metasploit integration cases work, added more test cases for PostgreSQL and code refactoring (issue #312 )
2013-01-14 13:42:50 +00:00
Bernardo Damele
279f6cb9ce
minor bug fix for PostgreSQL --file-read
2013-01-14 12:22:15 +00:00
Bernardo Damele
bd89ade02f
minor bug fix for PostgreSQL --file-read
2013-01-14 12:22:00 +00:00
Bernardo Damele
c6d4b89869
minor bug fix for PostgreSQL (issue #338 )
2013-01-14 11:41:30 +00:00
Bernardo Damele
515c1c6205
removed leftover
2013-01-14 10:26:22 +00:00
Bernardo Damele
146d9fedf0
fix for bug #337
2013-01-14 10:24:45 +00:00
Bernardo Damele
b35b8a4835
fixed regexps for --live-test (issue #312 )
2013-01-14 10:24:11 +00:00
Bernardo Damele
83000de9e1
improved handling and storing of exceptions with --live-test ( #312 )
2013-01-14 10:23:40 +00:00
Bernardo Damele
8125fe90a7
code refactoring
2013-01-14 10:22:38 +00:00
Bernardo Damele
4acb281414
added first test cases for PostgreSQL
2013-01-14 01:11:57 +00:00
Bernardo Damele
036b612bcb
bug fix to be able to write unicode chars to debug file
2013-01-14 01:11:42 +00:00
Miroslav Stampar
fc560f2b75
Minor revert and proper fix
2013-01-14 00:47:29 +01:00
Bernardo Damele
b74cfbf336
minor enhancements for debug purposes (issue #312 )
2013-01-13 23:15:56 +00:00
Bernardo Damele
fdd6075859
temporary patch to fix UNION query enumeration
2013-01-13 23:08:23 +00:00
Miroslav Stampar
92ea8841f8
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-13 16:23:09 +01:00
Miroslav Stampar
03dd958d96
Implementation for an Issue #48
2013-01-13 16:22:43 +01:00
Bernardo Damele
327db5458d
755 is ok for the main files - issue #333
2013-01-11 15:15:58 +00:00
Miroslav Stampar
81848c723d
Minor cleanup (we officially support Python >= 2.6)
2013-01-11 16:01:48 +01:00
Bernardo Damele
675e4a026b
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-11 13:31:49 +00:00
Bernardo Damele
41834e7a5b
working on #8 - still not usable though
2013-01-11 13:31:44 +00:00
Miroslav Stampar
db91137eda
Fix for an Issue #333
2013-01-11 14:09:30 +01:00
Bernardo Damele
2a2d7e886d
align to MSSQL connector
2013-01-11 10:52:03 +00:00
Miroslav Stampar
cd420468f3
Minor update of doc/THANKS
2013-01-11 11:24:51 +01:00
Miroslav Stampar
bc4d8d3e02
Implementation for an Issue #332
2013-01-11 11:17:41 +01:00
Miroslav Stampar
5571d09354
Minor revert
2013-01-11 11:13:55 +01:00
Miroslav Stampar
4b79269608
Minor bug fix
2013-01-11 11:10:18 +01:00
Miroslav Stampar
ec4e49d771
Minor refactoring
2013-01-10 16:09:28 +01:00
Miroslav Stampar
1363f26367
Minor refactoring
2013-01-10 15:59:02 +01:00
Miroslav Stampar
834be1eddc
Restyling redundant 'except Exception' form
2013-01-10 15:54:28 +01:00
Miroslav Stampar
acfeeb4f51
Restyling old form of urlparse
2013-01-10 15:41:07 +01:00
Miroslav Stampar
da7f63f125
cx_Oracle.DatabaseError is an ancestor of cx_Oracle.InternalError
2013-01-10 15:33:32 +01:00
Miroslav Stampar
8686c20fa5
Removing one obsolete instantiation line
2013-01-10 15:27:35 +01:00
Miroslav Stampar
934d41dac2
Minor style update (PEP8)
2013-01-10 15:02:28 +01:00
Miroslav Stampar
ca3d35a878
Some PEP8 related style cleaning
2013-01-10 13:18:44 +01:00
Miroslav Stampar
6cfa9cb0b3
Removing unused imports
2013-01-10 12:15:12 +01:00
Miroslav Stampar
05705857a9
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-10 12:09:48 +01:00
Miroslav Stampar
ca1c0c2a1d
Minor style update
2013-01-10 11:54:07 +01:00
Miroslav Stampar
7ea846e111
Removing some junk from queries.xml
2013-01-10 11:46:51 +01:00
Miroslav Stampar
ebde4b190e
Minor update
2013-01-10 11:42:37 +01:00
Bernardo Damele
ca337159f5
added reminder TODO
2013-01-10 01:11:22 +00:00
Bernardo Damele
8093f3950d
properly distinguish stdout from stderr with a separate pipe (tracebacks go to stderr) - issue #297
2013-01-10 00:52:44 +00:00
Bernardo Damele
10f1099944
remove logging handler that shows logging messages to stdout - issue #297
2013-01-10 00:51:56 +00:00
Bernardo Damele
ccc3c3d1a3
minor fix to distinguish stdout from stderr
2013-01-10 00:51:05 +00:00
Bernardo Damele
ef40779ad3
upgraded to use custom subprocessng for non-blocking send and read functions for spawned processes. Added new method to display range of log messages, just in case and improved parsing/unpickling of read log messages
2013-01-10 00:01:28 +00:00
Bernardo Damele
2126a5ba12
minor index fix
2013-01-10 00:00:00 +00:00
Bernardo Damele
9766f6025e
logging is now handled in a separate file descriptor :) - issue #297
2013-01-09 22:09:50 +00:00
Bernardo Damele
794700eb37
preparing to handle logging calls by a separate file descriptor when sqlmap is executed by the REST API - issue #297
2013-01-09 22:08:50 +00:00
Bernardo Damele
d120dc18d1
cleanup
2013-01-09 22:06:27 +00:00
Bernardo Damele
58a60562ac
avoid exiting with a traceback for missing dependency, handle properly at some point
2013-01-09 16:05:55 +00:00
Bernardo Damele
7f4ce4afbb
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-09 16:04:29 +00:00
Bernardo Damele
510ceb6e19
first attempt to have --os-pwn and other takeover switches work across Windows and Linux - issue #28
2013-01-09 16:04:23 +00:00
Miroslav Stampar
bf5544903b
Minor style update
2013-01-09 16:10:26 +01:00
Miroslav Stampar
9bdcb1176d
Update for an Issue #169
2013-01-09 15:58:13 +01:00
Miroslav Stampar
25f01a419f
Minor style update (for the sake of consistency over the code and our PEP8 adaptation)
2013-01-09 15:38:41 +01:00
Miroslav Stampar
bdd2592848
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-09 15:22:30 +01:00
Miroslav Stampar
3d4f381ab5
Patch for an Issue #169
2013-01-09 15:22:21 +01:00
Bernardo Damele
c44a829b9b
pass a pickled options object to sqlmap engine when called from API
2013-01-09 12:34:45 +00:00
Bernardo Damele
8457cff278
added variable to store the live test traceback if any
2013-01-09 12:33:18 +00:00
Bernardo Damele
f11747732e
added missing command line options
2013-01-09 12:30:13 +00:00
Miroslav Stampar
55a552ddc4
Update for an Issue #24
2013-01-08 10:55:25 +01:00
Miroslav Stampar
614f4657f1
Removing timedelay tags inside queries.xml as we don't use those outside the payloads.xml anymore (Update for an Issue #24 )
2013-01-08 10:30:01 +01:00
Miroslav Stampar
ad85c4c964
Minor refactoring for an Issue #295
2013-01-08 10:23:02 +01:00
Bernardo Damele
c155c6df84
minor bug fix for user's provided LIMIT'd statement when technique is full UNION SQLi
2013-01-07 23:31:11 +00:00
Bernardo Damele
019fca84a2
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-07 23:12:31 +00:00
Miroslav Stampar
3abe87ac89
Minor fix with status update (Issue #305 )
2013-01-07 18:53:08 +01:00
Bernardo Damele
f8c5ec7daf
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-07 17:40:14 +00:00
Miroslav Stampar
a8f02916a9
Minor fix (Issue #305 )
2013-01-07 18:39:35 +01:00
Bernardo Damele
2c9a47f6f3
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-07 17:39:27 +00:00
Bernardo Damele
ec7508ec4f
test case to reproduce bug introduced at 76839ff
2013-01-07 17:39:13 +00:00
Miroslav Stampar
e219fad8bf
Added a short comment
2013-01-07 18:19:48 +01:00
Bernardo Damele
8ee840bc8e
maintained release is on Google code
2013-01-07 17:11:14 +00:00
Bernardo Damele
1e35b3c8c9
proper link
2013-01-07 16:59:59 +00:00
Miroslav Stampar
96e5d5d178
Some more updates for an Issue #295
2013-01-07 16:55:41 +01:00
Miroslav Stampar
74552bea87
Cleaning some garbage (hard coded paths with linux native slashes)
2013-01-07 16:51:00 +01:00
Miroslav Stampar
425df067eb
Fix for an --os-pwn with ICMPsh (it was crashing because methods interleaved with Metasploit ones)
2013-01-07 16:44:22 +01:00
Miroslav Stampar
46e2ad53cd
Fix for an Issue #331
2013-01-07 16:36:29 +01:00
Miroslav Stampar
ac407ae4a1
Implementation for an Issue #295
2013-01-07 15:55:40 +01:00
Miroslav Stampar
6270e9337b
Minor cosmetics
2013-01-07 14:34:20 +01:00
Miroslav Stampar
76839ff9d6
Fix for an Issue #305
2013-01-07 12:52:55 +01:00
Bernardo Damele
1e1892c962
prep for subprocess..
2013-01-07 11:10:33 +00:00
Bernardo Damele
7fa75792dd
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2013-01-07 11:10:08 +00:00
Bernardo Damele
a30d7014b9
removed unused var
2013-01-07 11:05:33 +00:00
Miroslav Stampar
87e923613f
Minor adjustment (URI (marked with custom injection char) has precedence over GET/POST)
2013-01-05 21:16:47 +01:00
Miroslav Stampar
dc21f3ce67
Minor just in case filtering of union results
2013-01-04 17:09:07 +01:00
Miroslav Stampar
5b77b20e2e
Removing trailing whitespaces (PEP8)
2013-01-03 23:57:07 +01:00
Miroslav Stampar
82b468211d
Minor update
2013-01-03 23:38:29 +01:00
Miroslav Stampar
f340ce8b4b
Minor style update
2013-01-03 23:35:29 +01:00
Miroslav Stampar
1712603dce
Replacing deprecated has_key() with operator in (PEP8)
2013-01-03 23:28:07 +01:00
Miroslav Stampar
e4a3c015e5
Replacing old and deprecated raise Exception style (PEP8)
2013-01-03 23:20:55 +01:00
Bernardo Damele
3a11d36c66
minor bug fix
2013-01-02 21:49:15 +00:00
Miroslav Stampar
cb15fcc8af
Fix for an Issue #329
2013-01-02 22:17:06 +01:00
Miroslav Stampar
304e52cb4d
Minor language update
2013-01-02 22:11:59 +01:00
Miroslav Stampar
09f1cdd8e1
Minor style update
2013-01-02 21:52:50 +01:00
Miroslav Stampar
0795760255
Minor fix
2012-12-30 11:22:23 +01:00
Miroslav Stampar
75edb84a71
Minor update
2012-12-30 11:10:32 +01:00
Miroslav Stampar
58ad2f1c5d
Revert of last commit and proper fix
2012-12-29 10:35:05 +01:00
Miroslav Stampar
0e18fa9c5f
Minor fix
2012-12-28 23:43:47 +01:00
Miroslav Stampar
648d91d790
Distinguishing invalid unicode from safe encoded characters (for proper potential decoding)
2012-12-27 22:43:39 +01:00
Miroslav Stampar
3d01890147
Patch for an Issue #56 (full target url is now being written to a output .CSV file in multi target mode)
2012-12-27 21:15:44 +01:00
Miroslav Stampar
cb91729913
Fix for an Issue #324 (crawling when HTML is not well-formed)
2012-12-27 20:55:37 +01:00
Miroslav Stampar
127b880577
Minor update
2012-12-27 15:14:40 +01:00
Miroslav Stampar
6ae4590edc
Removing problematic per-MySQL LIMIT prefix
2012-12-26 19:48:01 +01:00
Miroslav Stampar
568bd2da83
Trivial update
2012-12-26 17:15:59 +01:00
Miroslav Stampar
8b7cbe03b0
Replacing CRLF with LF in rest of files
2012-12-26 17:12:17 +01:00
Miroslav Stampar
eea249c991
Minor update
2012-12-26 16:43:38 +01:00
Miroslav Stampar
d7b84b6831
Minor modification
2012-12-26 12:58:52 +01:00
Miroslav Stampar
a6671ebb57
adding new file
2012-12-26 12:55:42 +01:00
Miroslav Stampar
a77b7f00d9
Fix for an Issue #323
2012-12-23 19:34:35 +01:00
Bernardo Damele
832567ecf6
import order
2012-12-21 23:34:37 +00:00
Miroslav Stampar
77625e5af7
Minor revert
2012-12-21 19:31:05 +01:00
Miroslav Stampar
00e55828e4
Minor style update
2012-12-21 15:06:03 +01:00
Miroslav Stampar
8b3e17ed4d
Minor update (better approach for those old NOT IN cases in MsSQL - instead of standard pivot dump table)
2012-12-21 14:52:47 +01:00
Miroslav Stampar
2fc187489b
Removing leftover
2012-12-21 14:01:59 +01:00
Miroslav Stampar
a3f9741d6e
Fixed unneeded trimming in --hex for MsSQL
2012-12-21 11:40:18 +01:00
Miroslav Stampar
6c1ec9b54f
Fix for an Issue #318
2012-12-21 11:10:05 +01:00
Miroslav Stampar
35728fa443
Fix (and some hidden bug fixes/improvements) regarding an Issue #317
2012-12-21 10:51:35 +01:00
Miroslav Stampar
352e516400
Bottle is a 3rd party tool (not going to extra folder)
2012-12-21 10:18:30 +01:00
Miroslav Stampar
0f62e677b5
Minor just in case commit (plural/singular unArrayize())
2012-12-21 10:15:42 +01:00
Miroslav Stampar
b94a5d42d4
Removing a leftover
2012-12-21 09:49:09 +01:00
Miroslav Stampar
0a122ccce4
Related to an Issue #319
2012-12-21 09:47:58 +01:00
Miroslav Stampar
0d5d84edc7
Minor cleanup
2012-12-20 21:03:41 +01:00
Miroslav Stampar
712cf4e4db
Fix for an Issue #316
2012-12-20 20:55:59 +01:00
Miroslav Stampar
1073ebc697
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-12-20 20:51:41 +01:00
Bernardo Damele
89d8c58fd1
poor attempt at forking a child process for sqlmap engine execution, output is not handled yet
2012-12-20 17:56:53 +00:00
Bernardo Damele
912323c12d
minor bug fix ( #297 )
2012-12-20 17:05:44 +00:00
Bernardo Damele
7adaffa71b
fixed options initiation
2012-12-20 16:53:43 +00:00
Miroslav Stampar
1c4d438aff
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-12-20 16:37:03 +01:00
Bernardo Damele
b0635bddcc
adjustments
2012-12-20 15:29:23 +00:00
Miroslav Stampar
cf763670dd
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-12-20 16:26:58 +01:00
Bernardo Damele
12eadcf07c
now api can only be run with sqlmapapi.py
2012-12-20 14:59:11 +00:00
Miroslav Stampar
8efe056671
Minor refactoring
2012-12-20 15:51:03 +01:00
Miroslav Stampar
2ac99e5021
Minor update
2012-12-20 15:40:56 +01:00
Bernardo Damele
e9ab33e9dd
standalone REST API, code cleanup ( #297 )
2012-12-20 14:35:02 +00:00
Miroslav Stampar
d928cce122
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-12-20 14:58:41 +01:00
Miroslav Stampar
18f4a916ea
Minor fix
2012-12-20 14:58:26 +01:00
Bernardo Damele
5632279bf7
removed deprecated feature ( #287 )
2012-12-20 13:21:07 +00:00
Bernardo Damele
a56e384abb
updated VM..
2012-12-20 13:18:45 +00:00
Bernardo Damele
e39ac0f092
added OR boolean-based test case
2012-12-20 12:52:26 +00:00
Bernardo Damele
d019f75e63
for this test case verbose has to be set to 2 as we parse a DEBUG message
2012-12-20 11:48:34 +00:00
Miroslav Stampar
63d9b7a1f8
No character shall be left forgotten (no more ? in case that character was not properly being decoded by used charset)
2012-12-20 12:23:37 +01:00
Miroslav Stampar
728e061c53
Preventing double safe char encoding
2012-12-20 12:21:45 +01:00
Bernardo Damele
190e317992
fixed test case and added new one, commented out metasploit integration case as it cannot be handled easily
2012-12-20 11:05:11 +00:00
Miroslav Stampar
c2c4601d6e
Minor restyling
2012-12-20 11:06:52 +01:00
Miroslav Stampar
19e2f3bb76
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-12-20 10:43:54 +01:00
Miroslav Stampar
03215ef209
Proper length function used now (fixing issues with international letters in multi threaded mode)
2012-12-20 10:43:38 +01:00
Bernardo Damele
076b4063e6
these edits got overwritten from last commits
2012-12-20 09:42:44 +00:00
Miroslav Stampar
3cbe60b586
Proper fix
2012-12-20 10:37:20 +01:00
Miroslav Stampar
0d1ea7f05a
Merge branch 'master' of github.com:sqlmapproject/sqlmap
...
Conflicts:
lib/core/testing.py
2012-12-20 10:37:11 +01:00
Miroslav Stampar
da93e77eb2
Proper fix
2012-12-20 10:34:51 +01:00
Bernardo Damele
1d64742842
added more test cases
2012-12-20 09:31:17 +00:00
Bernardo Damele
ac77724970
attempt to handle standard input from --live-test
2012-12-20 09:30:48 +00:00
Bernardo Damele
2b6ee06de0
minor bug fix to correctly parse unicode chars
2012-12-20 09:30:13 +00:00
Miroslav Stampar
69310e47ce
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-12-20 09:54:39 +01:00
Miroslav Stampar
06d8213ffd
minor fix (reading of unicode xml files)
2012-12-20 09:53:08 +01:00
Bernardo Damele
86872956d5
minor bug fix (for PostgreSQL)
2012-12-19 22:55:31 +00:00
Bernardo Damele
77843f44fb
minor bug fix (issue #314 )
2012-12-19 22:49:02 +00:00
Bernardo Damele
602405c171
added more test cases
2012-12-19 18:30:04 +00:00
Bernardo Damele
a2c58847e6
fixed title
2012-12-19 18:29:00 +00:00
Bernardo Damele
357da43cea
slight improvement of live test engine and added misc test cases to xml
2012-12-19 17:28:41 +00:00
Bernardo Damele
3061eec7d8
added test case for web shell command execution and temporary test case for Metasploit integration (--os-pwn)
2012-12-19 16:39:13 +00:00
Bernardo Damele
85fcd27e2d
added support for random global variables
2012-12-19 15:58:06 +00:00
Bernardo Damele
12d34587cc
minor restyling
2012-12-19 14:34:34 +00:00
Bernardo Damele
326ff404fc
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-12-19 14:25:35 +00:00
Bernardo Damele
12eed58485
pointless restyling
2012-12-19 14:25:29 +00:00
Miroslav Stampar
37346fe8a3
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-12-19 15:23:57 +01:00
Miroslav Stampar
7ee98c7bff
Just for one girl out there waiting for this patch ;)
2012-12-19 15:23:38 +01:00
Bernardo Damele
3be90c97aa
forgot these
2012-12-19 14:12:45 +00:00
Bernardo Damele
cefb03c835
fixed bug related to issue #223
2012-12-19 14:12:09 +00:00
Bernardo Damele
27a12ae85b
restyling
2012-12-19 13:47:17 +00:00
Bernardo Damele
4b3b4eb374
commented out partial work
2012-12-19 13:47:04 +00:00
Bernardo Damele
3655d1f12a
revert change of name for now
2012-12-19 13:45:52 +00:00
Bernardo Damele
874e2176c6
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-12-19 13:43:00 +00:00
Bernardo Damele
4f0f729982
be more specific in standard output message as to whether or not the read file is same as remote file
2012-12-19 13:42:56 +00:00
Miroslav Stampar
23153e8088
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-12-19 14:29:08 +01:00
Miroslav Stampar
244901eda0
During --flush-session log file should be cleaned too (especially because of --live-tests)
2012-12-19 14:28:54 +01:00
Bernardo Damele
282aeb734f
ORDER BY does not play well with UNION query SQLi (related to issue #313 )
2012-12-19 13:21:16 +00:00
Bernardo Damele
259b345f1f
catch ImportError exception if libmagic is not installed
2012-12-19 13:10:54 +00:00
Bernardo Damele
128597ee7e
--run-case is now case insensitive
2012-12-19 12:45:46 +00:00
Bernardo Damele
b91c829103
minor bug fix (issue #310 )
2012-12-19 12:42:31 +00:00
Bernardo Damele
e583ba6826
no point retesting all for time-based too as it uses same engine of boolean-based
2012-12-19 12:35:36 +00:00
Bernardo Damele
2bc2c0431c
fixed test cases
2012-12-19 12:33:37 +00:00
Bernardo Damele
5ceadf02ae
fixed test cases now that MySQL test db has two more tables and removed old test cases, soon to be replaced with new ones for other DBMSes
2012-12-19 12:22:45 +00:00
Bernardo Damele
9149d77cc8
removed duplicate code - fixes issue #310
2012-12-19 12:17:56 +00:00
Bernardo Damele
54752a9101
typo fix
2012-12-19 11:44:58 +00:00
Bernardo Damele
d80744d3d5
preparation for issue #310
2012-12-19 11:40:00 +00:00
Bernardo Damele
f5450e9f0e
layout adjustment
2012-12-19 11:39:38 +00:00
Bernardo Damele
dee56b17c3
handle "LIMIT num" as well as "LIMIT num, num" across all techniques - fixes issue #308
2012-12-19 10:50:15 +00:00
Miroslav Stampar
155c1eddae
Debug message with declared page charset
2012-12-19 11:16:42 +01:00
Miroslav Stampar
d29dddf5b2
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-12-19 10:51:25 +01:00
Miroslav Stampar
92e338251a
Finally working inference against MySQL/international letters (even chinese)
2012-12-19 10:44:02 +01:00
Bernardo Damele
65ed2304fd
comment update
2012-12-19 09:38:03 +00:00
Bernardo Damele
9b422e1e94
minor fix for issue #309
2012-12-19 09:37:29 +00:00
Bernardo Damele
0037d52098
typo fix
2012-12-19 01:11:18 +00:00
Miroslav Stampar
c9b8b51c9c
Update lib/core/common.py
...
Revert of last commit and try 2
2012-12-19 01:48:53 +01:00
Bernardo Damele
8e95470415
minor refactoring
2012-12-19 00:46:23 +00:00
Bernardo Damele
318fcee49c
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-12-19 00:30:26 +00:00
Bernardo Damele
3c7007097a
minor refactoring
2012-12-19 00:30:22 +00:00
Miroslav Stampar
50b846b5af
Update lib/core/common.py
...
Fixing wrong assumption in case of MySQL inference international character retrieval
2012-12-19 01:26:12 +01:00
Bernardo Damele
aeda67e945
updated third-party magic library
2012-12-18 23:58:49 +00:00
Miroslav Stampar
9e2f0131b9
Update lib/core/agent.py
2012-12-18 20:25:00 +01:00
Bernardo Damele
738dbde16c
avoid displaying "do you want to dump" message if no searched columns have been found
2012-12-18 18:07:34 +00:00
Bernardo Damele
326ed33f31
added support for comma separated list of files for --file-read - fixes issue #223
2012-12-18 17:55:21 +00:00
Bernardo Damele
8d9aa2c384
minor refactoring, added possibility to compare the remote file and downloaded file (--file-read), prepping for #223
2012-12-18 17:49:18 +00:00
Bernardo Damele
9a1eca20b5
lowered gravity
2012-12-18 16:42:03 +00:00
Bernardo Damele
58656bbeb5
minor bug fix, union query has to be limited 0, 0
2012-12-18 16:36:30 +00:00
Bernardo Damele
2c86022aab
added test cases for --sql-query and improved tests for --search -C
2012-12-18 16:30:46 +00:00
Bernardo Damele
f8267ece0f
added more specific --search -T and -C test cases
2012-12-18 16:13:38 +00:00
Bernardo Damele
61a838bb35
added more test cases
2012-12-18 15:59:48 +00:00
Bernardo Damele
d1d99d930b
proper fix for #306
2012-12-18 15:31:30 +00:00
Miroslav Stampar
30201d29bd
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-12-18 16:03:49 +01:00
Miroslav Stampar
88d8494b5a
Implementation for an Issue #307
2012-12-18 16:03:35 +01:00
Bernardo Damele
6b1dd05e62
reverted
2012-12-18 14:51:04 +00:00
Bernardo Damele
e1b7a6350e
consistency between --tables and --columns when -T and -C are respectively provided - there was a leftover from when --search called getColumns() as --columns: this is no longer the case (closes issue #306 )
2012-12-18 14:37:04 +00:00
Bernardo Damele
57412f8475
default to --search shall stay LIKE
2012-12-18 13:55:26 +00:00
Bernardo Damele
3fa05374bd
added tests for all MySQL techniques now (except stacked queries (S) as it is not supported on MySQL/PHP)
2012-12-18 12:07:19 +00:00
Miroslav Stampar
eb23b1b1a5
Minor commit related to the last one (uniq roles/privileges)
2012-12-18 12:47:06 +01:00
Miroslav Stampar
699a0f756a
Minor fix
2012-12-18 12:43:23 +01:00
Miroslav Stampar
7f47623876
Minor patch
2012-12-18 11:10:06 +01:00
Miroslav Stampar
9b716eb805
Implementation for an Issue #135
2012-12-18 10:13:42 +01:00
Miroslav Stampar
f56b846864
Patch for an Issue #300
2012-12-18 09:55:33 +01:00
Miroslav Stampar
2b64c10710
Patch for an Issue #304
2012-12-18 09:36:26 +01:00
Miroslav Stampar
45d6fdcdc8
Trivial update
2012-12-17 17:16:11 +01:00
Miroslav Stampar
175cb245cb
Adding common data type to txt/common-outputs (--columns --predict-output)
2012-12-17 17:13:51 +01:00
Bernardo Damele
4cd4f291d7
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-12-17 14:13:39 +00:00
Bernardo Damele
a00cd9b3ea
syntax fix
2012-12-17 14:13:34 +00:00
Miroslav Stampar
4ea0c9e922
Another implementation for an Issue #302
2012-12-17 15:08:54 +01:00
Bernardo Damele
d2bd275652
refactoring
2012-12-17 14:07:28 +00:00
Bernardo Damele
3c1cead406
WHERE condition for error-based technique for --tables with --exclude-sysdbs was logically wrong, fixed now
2012-12-17 14:06:12 +00:00
Bernardo Damele
b957b4790b
regexp fix
2012-12-17 13:52:00 +00:00
Bernardo Damele
eb44f30d63
minor layout output fix
2012-12-17 13:51:46 +00:00
Bernardo Damele
3c1b696bd6
removed more print statements
2012-12-17 13:35:32 +00:00
Bernardo Damele
86bca05ab0
improved tests
2012-12-17 13:30:41 +00:00
Bernardo Damele
1fdd804e94
replaced instances of dataToStdout with logger
2012-12-17 13:30:21 +00:00
Bernardo Damele
9f47eb0a59
cleaner
2012-12-17 13:29:37 +00:00
Bernardo Damele
0500712a03
removed unuseful prints
2012-12-17 13:29:19 +00:00
Bernardo Damele
ac44cf3ec0
minor fix: add also back-end DBMS and web app fingerprint output to log file
2012-12-17 13:02:09 +00:00
Bernardo Damele
bbd2adb5fb
improvements to --live-test and added --stop-fail switch
2012-12-17 11:41:43 +00:00
Bernardo Damele
064d443d60
replaced unnecessary dataToStdout() call with appropriate logger.info() call
2012-12-17 11:30:08 +00:00
Bernardo Damele
2926c815bf
improved test switch --live-test and minor refactoring
2012-12-17 11:29:33 +00:00
Bernardo Damele
f40c52cc17
comment adjustment
2012-12-17 11:28:03 +00:00
Bernardo Damele
2442a58884
minor leftover of deprecated XMLRPC service
2012-12-17 11:26:31 +00:00
Miroslav Stampar
60baf5071e
Patch for an Issue #302
2012-12-17 00:40:01 +01:00
Bernardo Damele
d4a061d0c3
code cleanup - #297
2012-12-15 00:29:35 +00:00
Bernardo Damele
0c3da5c7eb
code refactoring and first time logger is handled by a separate file descriptor (issue #297 )
2012-12-15 00:12:22 +00:00
Bernardo Damele
2f6a31605c
code refactoring ( #279 )
2012-12-14 22:00:42 +00:00
Bernardo Damele
8dee8355c2
on our way to make it thread safe.. it is a long way actually (issue #297 )
2012-12-14 18:13:21 +00:00
Bernardo Damele
21ecffb750
added more comments, improved cleanup method
2012-12-14 17:21:19 +00:00
Bernardo Damele
b50ea26e7b
updated THANKS
2012-12-14 16:22:49 +00:00
Bernardo Damele
1421e6a9d4
implemented cleanup and status admin methods
2012-12-14 16:18:45 +00:00
Bernardo Damele
4fa2f400ec
minor fix
2012-12-14 15:55:30 +00:00
Bernardo Damele
4c4cb856ff
minor bug fix to the /scan/<taskid>output method, forced each taskid to have its own temporary folder for output - issue #297
2012-12-14 15:52:35 +00:00
Bernardo Damele
27906f388f
added first methods to interact with sqlmap core, it is now possible to launch a scan from the API, hurray! (issue #297 )
2012-12-14 14:51:01 +00:00
Bernardo Damele
f52d81c834
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-12-14 13:40:36 +00:00
Bernardo Damele
0b71c85d95
refactoring, code cleanup, more security-related headers and first /scan method implementation (issue #297 )
2012-12-14 13:40:25 +00:00
Bernardo Damele
a2a71bb37b
cleanup from XML-RPC related stuff
2012-12-14 13:37:36 +00:00
Miroslav Stampar
a3acf72e52
Fix for argparse issue
2012-12-14 14:35:11 +01:00
Miroslav Stampar
235631808f
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-12-14 14:25:02 +01:00
Bernardo Damele
3d9779ffd4
further improvements to RESTful API: enforce security headers across all HTTP responses properly and make consistent responses across methods ( #297 )
2012-12-14 12:15:04 +00:00
Bernardo Damele
7b43837238
cleaner solution for imports as standalone client/server (issue #297 )
2012-12-14 12:04:44 +00:00
Bernardo Damele
90d5696b25
enhanced RESTful API to support JSON requests and improved standalone client/server skeleton (issue #297 )
2012-12-14 12:01:13 +00:00
Bernardo Damele
156a291e2d
typo fix
2012-12-14 11:55:54 +00:00
Bernardo Damele
1bb8e6f744
updated third party document to reflect inclusion of bottle web framework ( #297 )
2012-12-14 11:40:35 +00:00
Miroslav Stampar
c41618416c
Removing trailing blanks
2012-12-14 12:00:45 +01:00
Bernardo Damele
2e97405ffa
bundle bottle library in sqlmap (it is MIT license) - issue #297
2012-12-14 03:00:30 +00:00
Bernardo Damele
0ec420cc70
leftovers
2012-12-14 02:54:16 +00:00
Bernardo Damele
a1b83cd56f
added first implementation of REST-JSON API library - issue #297
2012-12-14 02:52:31 +00:00
Bernardo Damele
6e31e87de1
added initial support (hidden from -hh and not yet usable) for REST-JSON API
2012-12-14 02:49:25 +00:00
Miroslav Stampar
46885d4c28
New pep8 script
2012-12-13 16:07:49 +01:00
Miroslav Stampar
c040323821
Minor update
2012-12-13 14:55:20 +01:00
Miroslav Stampar
df0f08bc6a
Cleaning some (web upload based) garbage
2012-12-13 13:19:47 +01:00
Miroslav Stampar
5150172178
Minor update
2012-12-13 10:03:21 +01:00
Miroslav Stampar
6d53d8d112
Minor fix
2012-12-12 18:04:50 +01:00
Miroslav Stampar
b78b56d782
Update for an Issue #287 regarding read_output returning values
2012-12-12 17:17:36 +01:00
Miroslav Stampar
76eb894bc7
Batch is a must in XML-RPC mode (Issue #287 )
2012-12-12 16:53:29 +01:00
Miroslav Stampar
fc4be0a77c
Minor fix
2012-12-12 16:45:29 +01:00
Miroslav Stampar
e381158058
Hmmm... Let me guess. Update for an Issue #287
2012-12-12 16:31:20 +01:00
Miroslav Stampar
921000bd87
Another update for an Issue #287
2012-12-12 14:22:24 +01:00
Miroslav Stampar
c3f20a136f
Minor update for an Issue #287
2012-12-12 14:03:03 +01:00
Miroslav Stampar
32b39c72e4
Minor update
2012-12-12 12:07:56 +01:00
Miroslav Stampar
af52e8e8c2
Minor update for an Issue #287
2012-12-12 12:01:18 +01:00
Miroslav Stampar
a6448e8768
Update for an Issue #287
2012-12-12 11:54:59 +01:00
Miroslav Stampar
ef33729381
Writing only unique hashes to an output file (for eventual cracking with 3rd party tools)
2012-12-12 09:59:24 +01:00
Miroslav Stampar
b9f6fc5f4e
First commit (and working one) for an Issue #287 (XML-RPC server)
2012-12-11 16:02:06 +01:00
Miroslav Stampar
b5884c7eda
Minor language update
2012-12-11 15:24:02 +01:00
Miroslav Stampar
760519dbe9
Removing redundant piece of code
2012-12-11 15:21:27 +01:00
Miroslav Stampar
a54c261496
Minor update for Issues #292 & #293 (only single alert per target)
2012-12-11 14:44:43 +01:00
Miroslav Stampar
5c2451d83c
Implementation for an Issue #293
2012-12-11 12:48:58 +01:00
Miroslav Stampar
cb13735788
Fix for an Issue #294
2012-12-11 12:14:33 +01:00
Miroslav Stampar
562044577b
Implementation for an Issue #292
2012-12-11 12:02:06 +01:00
Miroslav Stampar
9e38ccbc3d
Removing unused imports
2012-12-10 17:47:42 +01:00
Miroslav Stampar
6ec536e94d
Removing old shutils script and adding new one
2012-12-10 17:44:55 +01:00
Miroslav Stampar
d013644c65
Minor update
2012-12-10 17:37:43 +01:00
Miroslav Stampar
6433be8b3d
Style update
2012-12-10 17:20:04 +01:00
Miroslav Stampar
996e882e78
Minor update
2012-12-10 17:13:00 +01:00
Miroslav Stampar
013dc8bc98
Another minor update for an Issue #267
2012-12-10 13:07:36 +01:00
Miroslav Stampar
8bd0080bf4
Minor update for an Issue #267
2012-12-10 13:05:41 +01:00
Miroslav Stampar
96df0ba061
Implemented support for plain , chars too (Issue #267 )
2012-12-10 12:58:17 +01:00
Miroslav Stampar
d0ea4c65c5
Minor styl eupdate for an Issue #267
2012-12-10 12:54:01 +01:00
Miroslav Stampar
5677db02b7
Minor update
2012-12-10 12:40:28 +01:00
Miroslav Stampar
5606a860ce
Oracle supports inline comments too (Issue #267 )
2012-12-10 12:00:15 +01:00
Miroslav Stampar
a024884ca7
Support for a HTTP parameter pollution (Issue #267 )
2012-12-10 11:55:31 +01:00
Miroslav Stampar
42f4c2bac9
Minor fix when --dbms is enforced
2012-12-10 11:42:10 +01:00
Miroslav Stampar
1f7644a691
Minor fix when user doesn't want custom injection char marker to be processed
2012-12-08 21:23:30 +01:00
Miroslav Stampar
0cbdaaecfa
Revert of 99e9412f74 (because of an Issue #289 )
2012-12-08 08:53:25 +01:00
Miroslav Stampar
73968a448c
Minor update
2012-12-07 15:29:54 +01:00
Miroslav Stampar
e129a30e6b
Removing redundant code in redirect handler (related to an Issue #288 )
2012-12-07 12:40:19 +01:00
Miroslav Stampar
fccad15cfa
Minor update for an Issue #288
2012-12-07 12:14:33 +01:00
Miroslav Stampar
75e6d77fbc
Minor refactoring
2012-12-07 11:54:34 +01:00
Miroslav Stampar
fbaeecdaf9
Patch for an Issue #288
2012-12-07 11:52:21 +01:00
Miroslav Stampar
c0fc12beb2
Minor update for an Issue #288
2012-12-07 11:23:18 +01:00
Miroslav Stampar
ed1b5d0ada
Minor fix
2012-12-07 10:57:57 +01:00
Miroslav Stampar
b5c8707323
Infinite loop fix when 'SELECT DB_NAME(...)' method used for --dbs in MsSQL
2012-12-06 15:55:33 +01:00
Miroslav Stampar
1028afce37
Removal of leftovers
2012-12-06 14:15:44 +01:00
Miroslav Stampar
974407396e
Doing some more style updating (capitalization of exception classes; using _ is enough for private members - __ is used in Python specific methods)
2012-12-06 14:14:19 +01:00
Miroslav Stampar
003d21e962
Minor style update (capitalization of leftover class names)
2012-12-06 13:46:24 +01:00
Miroslav Stampar
bb397f3907
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-12-06 11:58:13 +01:00
Miroslav Stampar
baccbd6f48
Implementation for an Issue #283
2012-12-06 11:57:57 +01:00
Bernardo Damele
13a1baef20
Create CONTRIBUTING.md
2012-12-06 02:53:03 -08:00
Miroslav Stampar
ab67344448
Removed unused imports and variables (pyflake-ing)
2012-12-06 11:15:05 +01:00
Miroslav Stampar
b6650add46
Introducing 'new style classes' (idea from Pull request #284 )
2012-12-06 10:42:53 +01:00
Miroslav Stampar
0f191f624c
Taking some goodies from Pull request #284
2012-12-06 10:21:53 +01:00
Miroslav Stampar
6b39e661a7
Fix for an issue #279
2012-12-05 12:15:14 +01:00
Miroslav Stampar
bc72180a3b
Lowering --limit for inline query technique
2012-12-05 10:58:41 +01:00
Miroslav Stampar
775e0df04b
Update for an Issue #278
2012-12-05 10:45:17 +01:00
Miroslav Stampar
949fcb77cf
Minor style update
2012-12-05 10:22:16 +01:00
Miroslav Stampar
d4b5133df7
Update for an Issue #272
2012-12-04 17:04:32 +01:00
Miroslav Stampar
a14697e8cf
Implementation for an Issue #272
2012-12-04 16:47:34 +01:00
Miroslav Stampar
6b007ab188
Minor patch for an Issue #274 (just in case to avoid this kind of problems)
2012-12-04 16:14:14 +01:00
Miroslav Stampar
c636c26acc
Minor update
2012-12-03 17:43:39 +01:00
Miroslav Stampar
e2aa695655
Minor update
2012-12-03 17:20:18 +01:00
Miroslav Stampar
42a8234c6f
Update for an Issue #12
2012-12-03 14:27:01 +01:00
Miroslav Stampar
79fca8e9d5
Fix for an Issue #268
2012-12-03 12:13:59 +01:00
Miroslav Stampar
8410fc5a9d
Minor update
2012-12-02 08:00:55 +01:00
Bernardo Damele
da97cc085e
Merge pull request #269 from redshark1802/master
...
fixed typo, wrong datatype for the option 'notString'
2012-12-01 16:08:23 -08:00
redshark1802
1675386093
fixed typo that created an invalid configuration file with the option '--save'
2012-11-30 23:00:03 +01:00
Miroslav Stampar
0664e72bea
Minor fix for an Issue #230
2012-11-30 12:13:34 +01:00
Miroslav Stampar
5b61e9ce12
Minor update for an Issue #254
2012-11-30 11:43:50 +01:00
Miroslav Stampar
6ea07f7ba9
Fix of false statement (bluecoat.py was not meant to be used only against MySQL - Issue #261 )
2012-11-29 15:53:54 +01:00
Miroslav Stampar
7e2db762d6
Minor update
2012-11-29 15:45:04 +01:00
Miroslav Stampar
8f10023523
Fix for an Issue #266
2012-11-29 15:44:14 +01:00
Miroslav Stampar
3b961c2550
Update for an Issue #254
2012-11-29 15:36:38 +01:00
Miroslav Stampar
bdd819d7f2
Improvement of a between.py tamper script
2012-11-29 14:41:07 +01:00
Miroslav Stampar
605d73cc3d
Minor refactoring
2012-11-29 12:21:12 +01:00
Miroslav Stampar
2e2a7a34b6
Minor consistency update
2012-11-29 12:11:53 +01:00
Miroslav Stampar
b250b68231
Bug fix (--users was returning only 1 value because of this bug; probably introduced by mistake months ago)
2012-11-29 12:02:59 +01:00
Miroslav Stampar
7304971544
Patch for ORDER BY test on MsSQL on cases with 'The text, ntext, and image data types cannot be compared or sorted, except when using IS NULL or LIKE operator'
2012-11-29 11:43:49 +01:00
Miroslav Stampar
7c16bfe025
Fix for error-based MsSQL dumping (in some cases failed because of wrong order - e.g. MIN(SUBSTRING( instead of SUBSTRING(MIN )
2012-11-29 10:51:59 +01:00
Miroslav Stampar
a7e1e856d4
Fix for an Issue #260
2012-11-28 17:00:26 +01:00
Miroslav Stampar
35d1146fd1
Minor update for an (Issue #254 )
2012-11-28 12:53:11 +01:00
Miroslav Stampar
753d0f18bf
First CSS style added for a HTML table dump format (Issue #254 )
2012-11-28 12:46:43 +01:00
Miroslav Stampar
b6ea337937
First style-less prototype for an HTML dump output (Issue #254 )
2012-11-28 12:28:42 +01:00
Miroslav Stampar
e2d8b53e97
Minor update for an Issue #264
2012-11-28 11:45:33 +01:00
Miroslav Stampar
cff0c59630
Implementation for an Issue #264
2012-11-28 11:41:39 +01:00
Miroslav Stampar
5bf5b95588
More refactoring for an Issue #254
2012-11-28 11:16:00 +01:00
Miroslav Stampar
87a92ab330
Deprecating --replicate (Issue #254 )
2012-11-28 11:10:57 +01:00
Miroslav Stampar
f08eb0fd9f
Minor style update
2012-11-28 10:59:15 +01:00
Miroslav Stampar
d95dd2d16e
Preparation for an Issue #254
2012-11-28 10:58:18 +01:00
Miroslav Stampar
621ae587c7
Fix for an Issue #263
2012-11-28 00:03:17 +01:00
Miroslav Stampar
c0796b4742
Minor bug fix (RLIKE boolean case was using wrong comparison payload)
2012-11-27 12:03:38 +01:00
Miroslav Stampar
d490ffb163
Fix for an Issue #259
2012-11-27 11:45:22 +01:00
Miroslav Stampar
bd33128085
Fix for an Issue #262
2012-11-27 10:08:22 +01:00
Miroslav Stampar
ed40f18796
Minor fix
2012-11-26 14:59:44 +01:00
Miroslav Stampar
38c96a366b
Patch for an Issue #260
2012-11-26 11:16:59 +01:00
Miroslav Stampar
8fe8bea55c
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-11-21 10:16:39 +01:00
Miroslav Stampar
ef2038f1c8
Implementation for an Issue #253
2012-11-21 10:16:13 +01:00
Miroslav Stampar
735cfeee26
Update extra/shutils/_sqlmap.py
...
Minor language fix
2012-11-20 14:33:03 +01:00
Miroslav Stampar
237dc107e7
Merge pull request #252 from kost/zsh-completion
...
zsh completion script
2012-11-20 05:31:19 -08:00
Vlatko Kosturjak
209a860527
Initial import of zsh completion script
2012-11-20 12:54:07 +01:00
Miroslav Stampar
c40dded28c
Fix for an Issue #250
2012-11-20 12:10:29 +01:00
Miroslav Stampar
93e071fc33
Fix for an Issue #251
2012-11-20 11:19:23 +01:00
Miroslav Stampar
302348b0cd
Minor update
2012-11-19 11:59:28 +01:00
Miroslav Stampar
a40d7a5bca
Minor improvement (safer to use column name in COUNT than *, especially when only one column is needed)
2012-11-15 15:06:54 +01:00
Miroslav Stampar
d37be5f97b
Fix for an Issue #248
2012-11-14 15:54:24 +01:00
Miroslav Stampar
9a54a911a8
Patch for an Issue #231
2012-11-14 11:30:29 +01:00
Miroslav Stampar
5b3fe25211
Improving comparison engine (removing shared prelude part to further sharpen if pages are identical - especially noticable in small test pages)
2012-11-13 15:22:59 +01:00
Miroslav Stampar
6f7f9dd8eb
Patch for an Issue #242
2012-11-13 10:41:13 +01:00
Miroslav Stampar
a52dbc575b
Patch for an Issue #246
2012-11-13 10:21:11 +01:00
Miroslav Stampar
f305dde413
Patch for an Issue #235
2012-11-10 11:01:29 +01:00
Miroslav Stampar
181c3534f0
Patch for an Issue #237
2012-11-08 19:16:37 +01:00
Miroslav Stampar
e7e83defaa
Minor update
2012-11-08 11:09:34 +01:00
Miroslav Stampar
1ee0d9ce5e
Fix for an Issue #229
2012-11-05 15:58:54 +01:00
Miroslav Stampar
3cf5fc2f5a
Fix for an Issue #230
2012-11-05 15:10:49 +01:00
Miroslav Stampar
5352b3ebd9
Refactoring code in tamper/bluecoat.py
2012-11-05 13:09:53 +01:00
Miroslav Stampar
d75598fccf
Merge pull request #232 from Th4nat0s/master
...
Tamper for SGos BlueCoat recommended Waf configuration
2012-11-05 03:53:37 -08:00
Thanatos
60aa7a7cd0
Tamper for BlueCoat SGos WAF
2012-11-03 19:15:22 +01:00
Miroslav Stampar
2de52927f3
Code refactoring (epecially Google search code)
2012-10-30 18:38:10 +01:00
Miroslav Stampar
76b793b199
Fix for an Issue #228
2012-10-30 18:08:25 +01:00
Miroslav Stampar
6e2041bc13
Better language than in last commit
2012-10-30 11:54:21 +01:00
Miroslav Stampar
1bbeb92eb6
Better language (used formation 'not required' in case of help for --dependencies while 'required'->'needs' in a check itself)
2012-10-30 11:19:39 +01:00
Miroslav Stampar
5cfc066ac4
Minor update
2012-10-30 10:30:22 +01:00
Miroslav Stampar
7c7aff12c6
Update for an Issue #225
2012-10-30 01:26:19 +01:00
Miroslav Stampar
969259607c
Minor update
2012-10-30 01:23:01 +01:00
Miroslav Stampar
b0f5b4f9bc
Update for an Issue #225
2012-10-30 00:59:31 +01:00
Miroslav Stampar
726de868e2
Fix for an Issue #225
2012-10-30 00:37:43 +01:00
Miroslav Stampar
a9094a35fe
Fix for an Issue #227
2012-10-30 00:20:49 +01:00
Miroslav Stampar
1d07b93730
Bug fix for --os-shell on MySQL (it was not working for a long time because of this)
2012-10-29 15:45:30 +01:00
Miroslav Stampar
5358d85d37
Important refactoring for web-based functionality
2012-10-29 15:09:05 +01:00
Miroslav Stampar
81ccf28785
Minor refactoring
2012-10-29 14:08:48 +01:00
Miroslav Stampar
d6e16e8641
Minor update
2012-10-29 11:08:02 +01:00
Miroslav Stampar
359e734954
Minor refactoring
2012-10-29 10:48:49 +01:00
Miroslav Stampar
32181d9322
minor update
2012-10-29 10:10:33 +01:00
Miroslav Stampar
919f75db9b
Improvement and fix for pivotDumpTable mechanism
2012-10-28 23:09:35 +01:00
Miroslav Stampar
d7973c3e32
Improvement of pivotDumpTable mechanism (no more fail on first entry)
2012-10-28 22:18:22 +01:00
Miroslav Stampar
c1eb803ef5
Bug fix for MsSQL --hex --technique=E (NOT IN based queries were not working properly)
2012-10-28 21:16:51 +01:00
Miroslav Stampar
b75c52f93c
Minor display fix (in --hex mode)
2012-10-28 12:30:21 +01:00
Miroslav Stampar
25a5073281
Bug fix for --hex/--technique=B (especially MsSQL)
2012-10-28 12:22:33 +01:00
Miroslav Stampar
8617fe0d65
Bug fix for international letters decoded with --hex on MsSQL
2012-10-28 11:50:16 +01:00
Miroslav Stampar
ca427af8b3
Minor refactoring/improvement
2012-10-28 01:42:08 +02:00
Miroslav Stampar
43ddf39bea
Minor refactoring
2012-10-28 01:16:02 +02:00
Miroslav Stampar
bcdba7b7bb
Dealing with rare cases when getIdentifiedDbms is needed prior to DBMS isfingerprinted and there are multiples of dbmses inside details
2012-10-28 01:11:50 +02:00
Miroslav Stampar
c1b8226329
Massive renaming (proper naming is inband = union & error techniques! - query naming stays as they are/in code things like forgeInbandQuery are renamed to forgeUnionQuery)
2012-10-28 00:36:09 +02:00
Miroslav Stampar
a435ba6863
Minor fix
2012-10-28 00:19:00 +02:00
Miroslav Stampar
0aeb9dbe8b
Bug fix (in --dump mode if error/inband failed with None other techniques were ignored)
2012-10-27 23:42:52 +02:00
Miroslav Stampar
06805b27f2
Bug fix (time was also meant to be disabled in case of error/inband getvalues)
2012-10-27 23:16:25 +02:00
Miroslav Stampar
7207cf29dd
Minor update
2012-10-26 11:05:44 +02:00
Miroslav Stampar
965d7eee17
Minor bug fix for a reflection removal mechanism
2012-10-26 00:06:15 +02:00
Miroslav Stampar
235cc656b9
Fix for an Issue #224
2012-10-25 15:25:31 +02:00
Miroslav Stampar
bcf708f4b1
Minor update
2012-10-25 13:37:33 +02:00
Miroslav Stampar
fdcdd11cb9
Minor update for an Issue #222
2012-10-25 13:35:44 +02:00
Miroslav Stampar
8a5844a364
Implementation for an Issue #222
2012-10-25 13:21:32 +02:00
Miroslav Stampar
ba55bed008
More general approach for PostgreSQL concatenation operator precedence problem (Issue #219 )
2012-10-25 10:41:16 +02:00
Miroslav Stampar
afd82b92dd
Patch for an Issue #221
2012-10-25 10:21:36 +02:00
Miroslav Stampar
12fc9442b9
Tamper function(s) refactoring (really no need for returning headers as they are passed by reference)
2012-10-25 10:10:23 +02:00
Miroslav Stampar
54fbb22ab8
Minor refactoring
2012-10-25 09:56:36 +02:00
Miroslav Stampar
c2058dfc8f
Fix for an Issue #220
2012-10-25 09:42:43 +02:00
Miroslav Stampar
b7429dc6bb
Minor fix for an Issue #219
2012-10-25 00:15:59 +02:00
Miroslav Stampar
65ec715828
Fix for an Issue #218
2012-10-25 00:03:00 +02:00
Miroslav Stampar
c0f57f4e90
Minor fix for an Issue #217
2012-10-24 23:43:28 +02:00
Miroslav Stampar
344ef9af7d
Language fix (in lots of cases wrong statement 'unable to retrieve columns for any table in database' was reported)
2012-10-24 23:38:35 +02:00
Miroslav Stampar
5477c9f7ba
Fix for an Issue #216
2012-10-24 22:59:46 +02:00
Miroslav Stampar
056be32ac1
Fix for Issue #213
2012-10-23 17:06:31 +02:00
Miroslav Stampar
99ceea5eae
Fix for an Issue #214
2012-10-23 17:05:45 +02:00
Miroslav Stampar
f3aa09c794
Minor language fix
2012-10-23 15:52:43 +02:00
Miroslav Stampar
6e2fce66aa
Patch for an Issue #212
2012-10-23 15:34:59 +02:00
Miroslav Stampar
eb6f17b561
Fix for --dump and -d=mssql
2012-10-23 15:02:43 +02:00
Miroslav Stampar
4365c48e83
Minor style update
2012-10-23 14:38:24 +02:00
Miroslav Stampar
06f226c494
Fix for an Issue #211
2012-10-23 14:37:45 +02:00
Miroslav Stampar
b82eb3a1ae
Fix for an Issue #210
2012-10-23 13:58:25 +02:00
Miroslav Stampar
f2bbf1ead9
Fix for raw_input raising EOFError and KeyboardInterrupt on Ctrl-C (Windows platform)
2012-10-23 11:05:00 +02:00
Miroslav Stampar
5ff2e33c43
Minor fix
2012-10-23 10:54:26 +02:00
Miroslav Stampar
68d5faa287
Minor update
2012-10-23 10:46:17 +02:00
Miroslav Stampar
f25f5c9eeb
Minor fix
2012-10-23 10:33:30 +02:00
Miroslav Stampar
54d086f409
Minor fix
2012-10-23 10:02:10 +02:00
Miroslav Stampar
f11a640e99
Undo of a previous commit (pdb left inside)
2012-10-22 14:39:35 +02:00
Miroslav Stampar
b913e2123d
Displaying hex-decoded resulting output in --hex mode
2012-10-22 14:39:11 +02:00
Miroslav Stampar
029143880a
Displaying hex-decoded resulting output in --hex mode
2012-10-22 14:36:01 +02:00
Miroslav Stampar
39f565533a
In case on --no-cast DUMP_REPLACEMENTS should not be used
2012-10-22 14:13:30 +02:00
Miroslav Stampar
3f596cda85
Minor fix for --dump --technique=B when empty strings are returned
2012-10-22 11:49:23 +02:00
Miroslav Stampar
21481df239
Minor update for Issue #209
2012-10-21 19:00:37 +02:00
Miroslav Stampar
fb1497aa89
Minor update for Issue #209
2012-10-21 18:53:31 +02:00
Miroslav Stampar
261b286021
Fix for an Issue #209
2012-10-20 13:17:45 +02:00
Miroslav Stampar
6a271fe800
Update for an Issue #2
2012-10-19 11:29:03 +02:00
Miroslav Stampar
998eb70288
Minor update
2012-10-19 11:05:10 +02:00
Miroslav Stampar
987f167e12
Minor update
2012-10-19 11:03:54 +02:00
Miroslav Stampar
d65d9e25cd
Implementation for an Issue #2
2012-10-19 11:02:14 +02:00
Miroslav Stampar
688a2db27a
Fix for an Issue #208
2012-10-19 10:04:09 +02:00
Miroslav Stampar
64b4586883
Minor update
2012-10-18 11:36:12 +02:00
Miroslav Stampar
ea49fa2db2
Fix for an Issue #206
2012-10-18 11:11:20 +02:00
Miroslav Stampar
1cb2ca4195
Minor update
2012-10-18 10:55:27 +02:00
Miroslav Stampar
b5060c0010
Fix for an Issue #205
2012-10-16 14:28:46 +02:00
Miroslav Stampar
2cb1b054bb
Implementation for an Issue #79
2012-10-16 12:32:58 +02:00
Miroslav Stampar
3e64ab214e
Minor update
2012-10-16 10:28:59 +02:00
Miroslav Stampar
9ad58cb531
Implementation for an Issue #204
2012-10-16 10:24:05 +02:00
Miroslav Stampar
8b57e1fce6
Minor update for an Issue #203
2012-10-15 23:15:52 +02:00
Miroslav Stampar
ebe3f4c34c
Minor fix
2012-10-15 18:51:42 +02:00
Miroslav Stampar
42b2c85517
Minor cosmetics
2012-10-15 18:45:13 +02:00
Miroslav Stampar
c7cf8b2e80
Minor refactoring of direct()
2012-10-15 18:41:41 +02:00
Miroslav Stampar
91ea8e52b7
Minor patch for an Issue #201
2012-10-15 18:01:52 +02:00
Miroslav Stampar
048e720f69
Minor refactoring for an Issue #203
2012-10-15 17:55:57 +02:00
Miroslav Stampar
9aba690a60
Patch for an Issue #203
2012-10-15 16:23:41 +02:00
Miroslav Stampar
e440b096c5
Fix for an Issue #202
2012-10-15 12:24:30 +02:00
Miroslav Stampar
ed2d163269
Fix for an Issue #201
2012-10-14 17:53:55 +02:00
Miroslav Stampar
56832fe9c4
Better adjustTimeDelay() candidate algorithm
2012-10-11 14:23:53 +02:00
Miroslav Stampar
e61c4c22c9
Implementation for an Issue #200
2012-10-09 15:19:47 +02:00
Miroslav Stampar
cd9a47835b
Minor consistency update
2012-10-09 14:48:26 +02:00
Miroslav Stampar
8c5fb1b064
Minor update
2012-10-09 14:46:45 +02:00
Miroslav Stampar
ea12ccec77
Minor refactoring
2012-10-09 11:33:19 +02:00
Miroslav Stampar
10b0fd21dc
Fix for an Issue #198
2012-10-09 11:27:19 +02:00
Miroslav Stampar
5a91b6e622
Minor cleanup
2012-10-09 10:21:52 +02:00
Miroslav Stampar
8e7449ccd5
Minor update
2012-10-07 20:28:24 +02:00
Miroslav Stampar
ff205f088b
Minor update
2012-10-07 20:12:55 +02:00
Miroslav Stampar
cc3f387551
Patch for an Issue #127
2012-10-05 10:49:31 +02:00
Miroslav Stampar
ebc7088f94
Implementation for an Issue #128
2012-10-05 10:24:09 +02:00
Miroslav Stampar
098e446ca4
Adding support for generic XML POST data
2012-10-04 18:44:12 +02:00
Miroslav Stampar
f71b937add
Minor language cleanup
2012-10-04 18:28:36 +02:00
Miroslav Stampar
8865fe69d7
Minor cleanup
2012-10-04 18:26:07 +02:00
Miroslav Stampar
2fbd05c98f
Minor language update
2012-10-04 18:04:55 +02:00
Miroslav Stampar
d464678e10
Minor update for an Issue #49
2012-10-04 18:01:42 +02:00
Miroslav Stampar
84b05e2d18
Better treating of numeric values (Issue #49 )
2012-10-04 16:08:37 +02:00
Miroslav Stampar
31aa9be1c7
Minor update
2012-10-04 15:40:11 +02:00
Miroslav Stampar
9129dac77b
Minor fix for an Issue #134
2012-10-04 15:33:26 +02:00
Miroslav Stampar
5d2b534908
Minor update (Issue #49 )
2012-10-04 15:23:01 +02:00
Miroslav Stampar
5b59b6feb4
Removing junk part
2012-10-04 12:09:09 +02:00
Miroslav Stampar
d570e25b1b
Minor workflow update
2012-10-04 12:05:59 +02:00
Miroslav Stampar
eddc634ceb
Minor improvement (custom injection marks are now processed in order of appearance)
2012-10-04 11:52:40 +02:00
Miroslav Stampar
3764d230be
Minor fix for Issue #197 and Issue #49
2012-10-04 11:43:37 +02:00
Miroslav Stampar
dee6d2f9ff
Minor language update
2012-10-04 11:34:14 +02:00
Miroslav Stampar
461e5ebc5f
Work for Issue #197 and Issue #49
2012-10-04 11:25:44 +02:00
Miroslav Stampar
bcbf0571a5
Implementation for an Issue #49
2012-10-02 14:23:58 +02:00
Miroslav Stampar
763dc98311
Minor refactoring
2012-10-02 13:36:15 +02:00
Miroslav Stampar
a8aecaa036
Minor style update
2012-10-02 13:33:10 +02:00
Miroslav Stampar
19407b9aca
Minor update
2012-09-26 15:25:01 +02:00
Miroslav Stampar
6eae7013b6
Minor cosmetics
2012-09-26 15:03:12 +02:00
Miroslav Stampar
687f3991de
Cleaning/refactoring of bunch of stacked/suffix/comment stuff (e.g.
2012-09-26 11:27:43 +02:00
Miroslav Stampar
6bc5f44b20
Minor just in case update for an Issue #195 (safer behavior on forced charsets)
2012-09-25 15:09:07 +02:00
Miroslav Stampar
efe4c13ed1
Update regarding suffixQuery (user supplied --suffix should nullify any eventual payload comments)
2012-09-25 14:36:15 +02:00
Miroslav Stampar
ec43ceec40
Some more cleanup related to the last commit (unneeded manual crafting/unneeded closing with ;)
2012-09-25 14:29:22 +02:00
Miroslav Stampar
560e0fcb25
Minor cleanup
2012-09-25 14:21:57 +02:00
Miroslav Stampar
fccdb824bb
Patch for an Issue #193
2012-09-25 11:21:39 +02:00
Miroslav Stampar
c9e7e71ea2
Implementation for an Issue #195
2012-09-25 10:17:25 +02:00
Miroslav Stampar
9ca7b3e20e
Implementation for an Issue #194
2012-09-25 09:25:35 +02:00
Miroslav Stampar
d175decdfc
Fix for an Issue #190
2012-09-22 20:59:40 +02:00
Miroslav Stampar
a6eeebfca8
Fix for an Issue #188
2012-09-20 11:30:07 +02:00
Miroslav Stampar
67cfc3b492
Removing boundaries (it were meant to be used as 'parameter replace' logic but it's not doable for boundaries)
2012-09-17 22:36:40 +02:00
Miroslav Stampar
acad7a34a2
Minor update
2012-09-17 22:23:44 +02:00
Miroslav Stampar
9a1fbb8941
Fix for an Issue #185
2012-09-13 14:22:26 +02:00
Miroslav Stampar
75990b715d
Fix for an Issue #184
2012-09-13 10:20:24 +02:00
Miroslav Stampar
1ec9422fa2
Minor cleanup of standard wordlist (html entities, etc.)
2012-09-12 16:06:32 +02:00
Miroslav Stampar
e570858db9
Implementation for an Issue #183
2012-09-12 11:50:38 +02:00
Miroslav Stampar
a64438fb5c
Minor language update
2012-09-11 19:45:40 +02:00
Miroslav Stampar
05dced5418
Minor language update
2012-09-11 19:43:03 +02:00
Miroslav Stampar
511c3b8dcc
Update and fix for an Issue #182
2012-09-11 14:58:52 +02:00
Miroslav Stampar
10b671d625
Update for an Issue #182
2012-09-11 12:08:34 +02:00
Miroslav Stampar
12d33c7a38
Fix for Issue #180 and #181 (missing module from an Issue #179 )
2012-09-10 22:39:56 +02:00
Miroslav Stampar
959225af55
Minor fix
2012-09-10 19:28:15 +02:00
Miroslav Stampar
5c21395fe2
Minor update for an Issue #179
2012-09-10 19:26:51 +02:00
Miroslav Stampar
1f49e4ae36
Fix for an Issue #179
2012-09-10 19:23:24 +02:00
Miroslav Stampar
9a631331a5
Fix for an Issue #177
2012-09-08 20:22:13 +02:00
Miroslav Stampar
5d23d72ff5
Fix for an Issue #176
2012-09-08 17:58:03 +02:00
Miroslav Stampar
f26ea04e38
Fix for an Issue #175
2012-09-07 17:06:38 +02:00
Miroslav Stampar
e4bc471f81
Fix for an Issue #173
2012-09-07 10:09:19 +02:00
Miroslav Stampar
a3baf94e9b
Minor style update
2012-09-07 10:09:00 +02:00
Miroslav Stampar
cea5127ffd
Update for an Issue #6
2012-09-06 15:51:38 +02:00
Miroslav Stampar
c3d191e626
Minor update for an Issue #2
2012-09-06 14:13:54 +02:00
Miroslav Stampar
1e238b5a5a
Minor update
2012-09-06 13:36:34 +02:00
Miroslav Stampar
9451bfccaf
Update for Issue #163
2012-09-06 13:14:20 +02:00
Miroslav Stampar
dbce417cdd
Potential fix for an Issue #171
2012-09-02 22:48:41 +02:00
Miroslav Stampar
f6716cf7c0
Fix for an Issue #170
2012-09-01 23:52:00 +02:00
Miroslav Stampar
2170e64ca5
Minor bug fix
2012-08-31 19:48:45 +02:00
Miroslav Stampar
33980adaef
Another update for an Issue #79
2012-08-31 12:46:38 +02:00
Miroslav Stampar
b916db34a4
Another update for an Issue #79
2012-08-31 12:38:02 +02:00
Miroslav Stampar
47d162f391
Minor update (same but cleaner)
2012-08-31 12:27:40 +02:00
Miroslav Stampar
7286d89cb6
Few fixes for an Issue #79 (problem with case sensitivity of request get_header)
2012-08-31 12:15:09 +02:00
Miroslav Stampar
2806185989
Minor refactoring
2012-08-31 10:43:06 +02:00
Miroslav Stampar
74a5d41272
Minor update for an Issue #79
2012-08-31 10:24:47 +02:00
Miroslav Stampar
f79ed0fb76
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-08-30 14:22:35 +02:00
Miroslav Stampar
cdd3ed6abc
Minor bug fix
2012-08-30 14:22:18 +02:00
Bernardo Damele
852a1b9cbf
minor syntax fix
2012-08-30 10:49:21 +01:00
Miroslav Stampar
ff2c4b8de4
Update of doc/THANKS
2012-08-29 21:34:17 +02:00
Miroslav Stampar
a89d61415a
'Patch' for an Issue #167
2012-08-29 21:29:27 +02:00
Miroslav Stampar
c1c65a7167
Fix for an Issue #166
2012-08-29 20:21:45 +02:00
Miroslav Stampar
50d60275a1
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-08-26 15:46:38 +02:00
Miroslav Stampar
eb2d9f78ca
Fix for an Issue #164
2012-08-26 15:46:12 +02:00
Miroslav Stampar
2af1313010
Update README.md
2012-08-23 20:08:57 +03:00
Miroslav Stampar
9674b174ee
One more minor update related to last commit
2012-08-23 15:37:17 +02:00
Miroslav Stampar
b79247c197
Minor update
2012-08-23 15:22:14 +02:00
Miroslav Stampar
59ab3c7bdc
Updating server.xml with fresh banners
2012-08-23 11:01:57 +02:00
Miroslav Stampar
e9ae44c6fc
Implementation for an #162
2012-08-22 16:50:01 +02:00
Miroslav Stampar
0ad3846451
Minor language update
2012-08-22 16:10:56 +02:00
Miroslav Stampar
f1f6364690
Changing default readInput value on dictionary-based attack depending on conf.multipleTargets
2012-08-22 16:10:38 +02:00
Miroslav Stampar
a62a874d59
Update for an Issue #161 (changing default readInput value regarding the conf.multipleTargets)
2012-08-22 16:06:09 +02:00
Miroslav Stampar
4ab4fd1cb4
Minor update
2012-08-22 15:53:40 +02:00
Miroslav Stampar
52351e5d81
Update for an Issue #161 (now detecting format error messages too)
2012-08-22 15:51:47 +02:00
Miroslav Stampar
dbbfee6c93
Minor style update
2012-08-22 15:05:17 +02:00
Miroslav Stampar
a6d743ec4c
Minor console output fix (redundant newline has been displayed in case of rawInput)
2012-08-22 14:43:57 +02:00
Miroslav Stampar
d7cf0de090
Fixing INSERT/UPDATE generic boundaries (those previous few were junkies)
2012-08-22 14:12:51 +02:00
Miroslav Stampar
7b93108e7d
Favoring non-string specific boundaries in case of digit-like parameter values
2012-08-22 13:58:52 +02:00
Miroslav Stampar
25ee333e66
Minor language update
2012-08-22 12:00:17 +02:00
Miroslav Stampar
8a5042b6a4
Update for an #161 (preventing further skipping of non-heuristic parameters in ignore casted case)
2012-08-22 11:56:30 +02:00
Miroslav Stampar
7d0662da23
Update for an #161
2012-08-22 11:42:06 +02:00
Miroslav Stampar
61151447fe
Implementation of an Issue #161
2012-08-22 11:27:58 +02:00
Miroslav Stampar
6210ddfbd6
Minor refactoring
2012-08-22 11:00:39 +02:00
Miroslav Stampar
a927d94d39
Update for an Issue #155
2012-08-22 10:57:31 +02:00
Miroslav Stampar
32a36f1ff3
El Cosmeticado
2012-08-22 09:58:39 +02:00
Miroslav Stampar
2c66ca39f1
Wrong limit number has been used (MySQL LIMIT/OFFSET starts with 0)
2012-08-22 09:53:53 +02:00
Miroslav Stampar
ebab05cf7c
Fix for an Issue #158
2012-08-21 20:20:38 +02:00
Miroslav Stampar
f098955081
Update of doc/THANKS
2012-08-21 14:46:48 +02:00
Miroslav Stampar
9aec3d5233
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-08-21 14:37:33 +02:00
Miroslav Stampar
ad59abe018
Cleaning leftover
2012-08-21 14:37:09 +02:00
Miroslav Stampar
1b86fffc6d
Fix for an Issue #157
2012-08-21 14:36:04 +02:00
Miroslav Stampar
d421f9a618
Fix for an Issue #157
2012-08-21 14:34:19 +02:00
Miroslav Stampar
221f47ff50
Style update
2012-08-21 14:50:45 +03:00
Miroslav Stampar
80120e849f
Minor refactoring and update of sqlharvest.py
2012-08-21 13:37:16 +02:00
Miroslav Stampar
1bcf5a6b88
Some more dict refactorings
2012-08-21 11:30:01 +02:00
Miroslav Stampar
01f481c332
Minor refactoring of dictionaries
2012-08-21 11:19:15 +02:00
Miroslav Stampar
b9c63eb908
Fix for an Issue #156
2012-08-21 10:46:29 +02:00
Miroslav Stampar
b7415d36df
Minor refactoring
2012-08-21 10:28:25 +02:00
Miroslav Stampar
7a8ace78f9
Removing redundant newline char as logger already adds it's own
2012-08-21 09:58:40 +02:00
Miroslav Stampar
233b9a3815
Fix for Issue #150 and Issue #151 (urllib2 is automatically adding those)
2012-08-20 22:17:39 +02:00
Miroslav Stampar
8ee9feafb9
Making payloads a bit shorter (removing redundant space after comma character - e.g. in inband queries)
2012-08-20 21:57:25 +02:00
Miroslav Stampar
6f450ac8bf
Implementation for an Issue #155
2012-08-20 12:14:01 +02:00
Miroslav Stampar
823dde73ab
Minor cleanup
2012-08-20 11:40:49 +02:00
Miroslav Stampar
2b6123c4f8
Minor style update
2012-08-20 11:29:23 +02:00
Miroslav Stampar
e0d9fa8666
Minor style update
2012-08-20 11:28:41 +02:00
Miroslav Stampar
76338add17
Fix for an Issue #152
2012-08-20 10:41:43 +02:00
Miroslav Stampar
59078bb1b8
Fix for an Issue #154
2012-08-20 10:05:13 +02:00
Miroslav Stampar
4649450603
Fix for an Issue #137
2012-08-16 22:20:24 +02:00
Miroslav Stampar
0d8fca30c9
Fix for an Issue #59
2012-08-16 11:31:43 +02:00
Miroslav Stampar
1af81c0de4
Implementation of an Issue #149
2012-08-15 22:31:25 +02:00
Miroslav Stampar
f358ab2e73
Implementation of an Issue #147
2012-08-15 16:37:18 +02:00
Miroslav Stampar
74ee0ce78a
Fix for an Issue #148
2012-08-14 23:25:12 +02:00
Miroslav Stampar
36b55cf209
Proper fix for an Issue #145
2012-08-14 22:28:42 +02:00
Miroslav Stampar
ab35ab4e2a
Fix for an Issue #145
2012-08-14 18:52:45 +02:00
Miroslav Stampar
5929c89ba4
Fix for an Issue #143
2012-08-09 13:44:21 +02:00
Miroslav Stampar
4b4288dfc8
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-08-08 19:07:25 +02:00
Miroslav Stampar
b78163f99b
Update for Issue #138
2012-08-08 19:06:47 +02:00
Bernardo Damele
eee62e573e
minor update
2012-08-08 18:09:27 +03:00
Miroslav Stampar
5fc1e8bc12
Fix for an Issue #142
2012-08-08 14:21:13 +02:00
Miroslav Stampar
432b567584
Fix for an Issue #141
2012-08-08 00:03:58 +02:00
Miroslav Stampar
31ceb0cb6c
Fix for an Issue #140
2012-08-07 10:57:29 +02:00
Miroslav Stampar
fec8a5cc9d
Fix for an Issue #139
2012-08-07 00:50:58 +02:00
Miroslav Stampar
3a60d3bc2e
update of doc/THANKS
2012-08-06 19:05:34 +02:00
Miroslav Stampar
6fdbe4eb89
Fix by zhouhx@knownsec.com (better LIKE boundaries)
2012-08-06 19:04:23 +02:00
Miroslav Stampar
b483710927
Minor update of doc/THANKS
2012-08-03 14:04:48 +02:00
Miroslav Stampar
f797a6d813
Fix for an Issue #125
2012-07-31 13:06:45 +02:00
Miroslav Stampar
6f529542e3
Making those --string tips (containing escaped characters) decodable by sqlmap
2012-07-31 11:32:53 +02:00
Miroslav Stampar
142fc887f1
Fix for an Issue #129
2012-07-31 11:03:44 +02:00
Miroslav Stampar
bdbe8ff9d9
Fix for an Issue #132
2012-07-30 22:39:45 +02:00
Miroslav Stampar
47073f4afd
Implementation of an Issue #131
2012-07-30 21:50:46 +02:00
Miroslav Stampar
93d35fe522
Minor update regarding Issue #129
2012-07-30 21:43:32 +02:00
Miroslav Stampar
b9ac50faef
Minor bug fix
2012-07-30 12:09:20 +02:00
Miroslav Stampar
a86f9798b2
Minor refactoring together with a wider support for html entities
2012-07-30 11:21:32 +02:00
Miroslav Stampar
20a66567a3
Minor refactoring
2012-07-30 10:06:14 +02:00
Miroslav Stampar
60ebb97915
Update of THANKS file
2012-07-29 17:42:42 +02:00
Miroslav Stampar
cc2a916716
Fix for an Issue #126
2012-07-29 17:33:08 +02:00
Miroslav Stampar
1669c6bdb4
Another update for an Issue #28
2012-07-27 17:05:21 +02:00
Miroslav Stampar
6ffc5665d0
Update for Issue #28
2012-07-27 16:29:33 +02:00
Miroslav Stampar
07738004cc
Fix for an Issue #123
2012-07-27 10:02:47 +02:00
Miroslav Stampar
a5062c1e4f
Adding a warn message when --dns-domain is ignored (because of faster techniques)
2012-07-27 09:48:48 +02:00
Bernardo Damele
92c2b3bd4c
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-07-26 23:11:11 +01:00
Bernardo Damele
d492291744
working on issue #12
2012-07-26 23:11:07 +01:00
Miroslav Stampar
cba387a0a0
Minor speed up
2012-07-26 15:42:04 +02:00
Miroslav Stampar
efa99c4519
Implementation for an Issue #4
2012-07-26 14:07:05 +02:00
Miroslav Stampar
b3552494c4
Minor preparation for an Issue #48
2012-07-26 12:26:57 +02:00
Miroslav Stampar
3e9f1fe410
Minor style update
2012-07-26 12:13:16 +02:00
Miroslav Stampar
30f8d09651
Implementation for an Issue #70
2012-07-26 12:06:02 +02:00
Miroslav Stampar
57f2fccc24
Revert of a previous commit (actually missing mysql.db is a bonus in this kind of attack :)
2012-07-26 11:40:47 +02:00
Miroslav Stampar
ec96689556
Safer for provoking 'Subquery returns more than 1 row' state than potentially missing mysql.db
2012-07-26 11:39:51 +02:00
Miroslav Stampar
6878ef92b2
Style update
2012-07-26 11:22:00 +02:00
Miroslav Stampar
ab3160316f
Implementation of payloads for Issue #122
2012-07-26 11:17:09 +02:00
Miroslav Stampar
231f0f76b5
Fix for an Issue #119
2012-07-26 00:49:51 +02:00
Miroslav Stampar
cba77410a9
Minor style update
2012-07-26 00:08:49 +02:00
Miroslav Stampar
18b1d1efd6
Fix for an Issue #121
2012-07-26 00:02:38 +02:00
Bernardo Damele
4a0b55f651
slight update to doc
2012-07-25 11:23:02 +01:00
Bernardo Damele
b78ec4cf9f
change of email
2012-07-25 11:20:14 +01:00
Miroslav Stampar
2b60e61d54
Minor update for #119
2012-07-25 10:57:19 +02:00
Miroslav Stampar
922ea9d1f4
Update for Issue #118
2012-07-24 15:43:29 +02:00
Miroslav Stampar
f8c9868cb6
Implementation for an Issue #118
2012-07-24 15:34:50 +02:00
Miroslav Stampar
42f518b2d6
Minor update for letting unhandledExceptionMessage() do it's job if kb has not yet been initialized
2012-07-24 14:44:44 +02:00
Miroslav Stampar
ffc520b35f
Minor refactoring
2012-07-24 14:35:56 +02:00
Miroslav Stampar
5f11f9e176
Refreshing wordlist with a yahoo dump dict
2012-07-24 10:28:15 +02:00
Miroslav Stampar
7f4fa7c27d
Minor refactoring
2012-07-24 01:21:32 +02:00
Miroslav Stampar
b820975217
Improvement of decodeIntToUnicode()
2012-07-23 19:31:06 +02:00
Miroslav Stampar
1153b4563c
Minor update for an Issue #111
2012-07-23 18:44:50 +02:00
Miroslav Stampar
fccd69721e
Update for an Issue #111
2012-07-23 18:38:46 +02:00
Miroslav Stampar
ab9cb80602
Implementing Issue #111
2012-07-23 15:14:52 +02:00
Miroslav Stampar
6809449e31
Minor style update
2012-07-23 15:06:49 +02:00
Miroslav Stampar
63bf99ce77
Minor just in case update for an Issue #117
2012-07-23 14:46:43 +02:00
Miroslav Stampar
c6b724489b
Minor style update
2012-07-23 14:26:42 +02:00
Miroslav Stampar
a7d1a0c250
Implementation for an Issue #117
2012-07-23 14:14:22 +02:00
Miroslav Stampar
3279ce53a8
Minor style update
2012-07-23 13:57:38 +02:00
Miroslav Stampar
534eccc9aa
Fix for an Issue #115
2012-07-23 10:16:47 +02:00
Miroslav Stampar
1b6cb9442f
Fix for an Issue #114
2012-07-21 23:31:36 +02:00
Bernardo Damele
0a4b6431a8
minor bug fix - issue #112
2012-07-21 16:51:01 +01:00
Miroslav Stampar
95e0d46e3e
Fix for an Issue #110
2012-07-21 09:15:54 +02:00
Bernardo Damele
5bf8600be3
removed references
2012-07-21 00:34:14 +01:00
Bernardo Damele
34e77a8801
ported fix for issue #81 also to blind techniques
2012-07-21 00:20:32 +01:00
Bernardo Damele
3e21f3d07a
fixed --search -C too on MSSQL - issue #81
2012-07-21 00:08:40 +01:00
Bernardo Damele
60242f92c5
made --search -D on MSSQL consistent with other DBMSes - issue #81
2012-07-20 23:37:56 +01:00
Bernardo Damele
7f10b01265
same fix as previous commit for blind techniques
2012-07-20 22:35:20 +01:00
Bernardo Damele
b54ae107cc
major bug fix in --search with multiple -C provided
2012-07-20 22:29:48 +01:00
Bernardo Damele
45177cf93d
minor restyling
2012-07-20 22:29:30 +01:00
Bernardo Damele
16668e1b8d
leftover debug message
2012-07-20 21:48:29 +01:00
Bernardo Damele
b0ab837832
minor code refactoring and implemented issue #95
2012-07-20 21:46:36 +01:00
Bernardo Damele
9cb1c4c0d9
plugin refactoring - issue #22
2012-07-20 19:17:35 +01:00
Bernardo Damele
dba0a96c2e
fall-back to UNION technique if web file stager was not uploaded with LIMIT
2012-07-20 17:11:22 +01:00
Bernardo Damele
a1d2a7913b
minor fix
2012-07-20 16:44:27 +01:00
Bernardo Damele
d812699cb3
minor layout adjustment
2012-07-20 16:25:00 +01:00
Bernardo Damele
baeffbf149
added SQL file to write a file with LIMIT statement on MySQL
2012-07-20 16:20:53 +01:00
Bernardo Damele
cbe8f41746
minor code refactoring preparing for #96
2012-07-20 16:20:17 +01:00
Bernardo Damele
86df6037e3
reverted previous ugly hack for issue #110 , perhaps a better fix is possible
2012-07-20 16:01:04 +01:00
Bernardo Damele
1928d5464d
fixes issue #97
2012-07-20 15:56:14 +01:00
Bernardo Damele
224bce8604
layout improvements
2012-07-20 13:34:01 +01:00
Bernardo Damele
f14b4227fd
layout improvements
2012-07-20 13:25:15 +01:00
Bernardo Damele
7f4d412f37
layout improvements
2012-07-20 13:19:34 +01:00
Bernardo Damele
8d1dd400da
renamed two doc files
2012-07-20 13:16:30 +01:00
Bernardo Damele
b752fefabc
repetition
2012-07-20 12:44:03 +01:00
Bernardo Damele
f75235d38a
fixes issue #109
2012-07-20 12:36:36 +01:00
Bernardo Damele
1ded7d4113
update for issue #109
2012-07-20 12:28:57 +01:00
Bernardo Damele
b0cde24be4
minor layout adjustment
2012-07-20 12:05:41 +01:00
Bernardo Damele
7930dca4a7
minor layout adjustment
2012-07-20 12:05:04 +01:00
Bernardo Damele
c02d3be55e
minor layout adjustment
2012-07-20 12:04:04 +01:00
Bernardo Damele
ab97392162
minor layout adjustment
2012-07-20 12:03:07 +01:00
Bernardo Damele
2dd41b4b96
added THIRD-PARTY file to documentation - issue #109
2012-07-20 12:01:19 +01:00
Miroslav Stampar
f336afa913
Implementation for Issue #108
2012-07-20 09:48:09 +02:00
Miroslav Stampar
53cb105f50
Merge pull request #107 from jekil/master
...
Removed "How to Apply These Terms to Your New Program"
2012-07-20 00:27:10 -07:00
jekil
3e0e2f324f
Removed "How to Apply These Terms to Your New Programs"
2012-07-19 23:42:11 +02:00
Miroslav Stampar
dcf8a27f12
Implementation for an Issue #67
2012-07-18 14:24:10 +02:00
Miroslav Stampar
4fc462c4d9
Minor update for an Issue #105
2012-07-18 14:09:04 +02:00
Miroslav Stampar
2656b8fc51
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-07-18 13:32:57 +02:00
Miroslav Stampar
655dd55a6f
Implementation of an Issue #105
2012-07-18 13:32:34 +02:00
Bernardo Damele
245bba5b93
minor updates to documentation
2012-07-18 11:41:09 +01:00
Bernardo Damele
209f4b34e3
psyco lib is unmaintained now
2012-07-18 11:36:46 +01:00
Bernardo Damele
243a905788
more on issue #97
2012-07-17 23:07:16 +01:00
Bernardo Damele
c483e91445
added payloads for ORDER BY/GROUP BY time-based injections - issue #97
2012-07-17 22:52:28 +01:00
Miroslav Stampar
a4f5c1d2b5
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-07-17 15:06:08 +02:00
Miroslav Stampar
08244c7ebf
Fix for an Issue #104
2012-07-17 15:05:50 +02:00
Bernardo Damele
771e7a9fc3
Initial commit for issue #97
2012-07-17 10:13:09 +01:00
Miroslav Stampar
e30646a54f
Fix for an Issue #103
2012-07-17 10:36:22 +02:00
Miroslav Stampar
41d16e55cb
Typo fix ( #102 )
2012-07-17 09:13:19 +02:00
Bernardo Damele
224e6376a6
cleanup to README files
2012-07-17 00:32:32 +01:00
Bernardo Damele
7198e3185b
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-07-17 00:25:08 +01:00
Bernardo Damele
318a01b867
minor typo fixes
2012-07-17 00:25:02 +01:00
Miroslav Stampar
d6ceb7af5e
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-07-17 00:19:52 +02:00
Miroslav Stampar
81d15e5051
Fix for an Issue #101
2012-07-17 00:19:33 +02:00
Bernardo Damele
c9bbd14f34
slight update to documentation
2012-07-16 22:58:55 +01:00
Bernardo Damele
5f876bdbbe
minor adjustments
2012-07-16 22:50:29 +01:00
Bernardo Damele
8daa9bff43
dual license
2012-07-16 22:42:44 +01:00
Miroslav Stampar
c96e44b30c
Fix for an Issue #100
2012-07-16 23:28:01 +02:00
Miroslav Stampar
ffbbb10abb
Support for dotted identificator names
2012-07-16 23:13:21 +02:00
Bernardo Damele
52431402dd
minor fix to avoid cleanup() if web backdoor upload failed
2012-07-16 17:58:30 +01:00
Miroslav Stampar
e80e51ee48
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-07-16 16:06:56 +02:00
Miroslav Stampar
0e21cb54de
Minor fix related to Issue #94
2012-07-16 16:06:39 +02:00
Bernardo Damele
2cb3b99910
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-07-16 15:03:16 +01:00
Bernardo Damele
6c1f8ca860
minor update
2012-07-16 15:03:04 +01:00
Miroslav Stampar
1606f5857b
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-07-16 15:43:20 +02:00
Miroslav Stampar
0f64e1e6c1
Minor update for Issue #94 (not fixing it)
2012-07-16 15:43:02 +02:00
Bernardo Damele
f0cec72863
updated FAQ
2012-07-16 14:32:18 +01:00
Miroslav Stampar
d3c151133b
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-07-16 14:12:09 +02:00
Miroslav Stampar
5ab300a28b
Update of doc/THANKS
2012-07-16 14:11:53 +02:00
Bernardo Damele
e826c14441
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-07-16 12:07:01 +01:00
Bernardo Damele
d066fa6a2c
avoid redudancy of information between homepage/README/users manual
2012-07-16 12:06:52 +01:00
Miroslav Stampar
0eff977c63
Refactoring for Issue #91
2012-07-16 12:24:54 +02:00
Miroslav Stampar
4d759984b2
Implementation for Issue #91
2012-07-16 12:12:52 +02:00
Miroslav Stampar
c1a14257a4
Removing --disable... switches and making changes in default choice(s) for respectable sections
2012-07-16 11:31:51 +02:00
Miroslav Stampar
07a85874fe
Implementation for Issue #92
2012-07-16 11:07:47 +02:00
Bernardo Damele
bb8cd788e1
minor fix
2012-07-16 09:56:41 +01:00
Bernardo Damele
88fd1299dc
updated FAQ, generated from wikified version ( https://github.com/sqlmapproject/sqlmap/wiki/FAQ ) with pandoc
2012-07-16 00:33:35 +01:00
Bernardo Damele
299dfdd089
slight adjustment
2012-07-15 21:38:49 +01:00
Bernardo Damele
9b174e4041
started to update the documentation: it is now wikified on https://github.com/sqlmapproject/sqlmap/wiki/_pages and converted to standalone PDF with pandoc - issue #44
2012-07-15 02:29:55 +01:00
Bernardo Damele
4940610f38
removed deprecated metasploit module
2012-07-14 19:27:31 +01:00
Bernardo Damele
05331d1eb0
removed unnecessary files
2012-07-14 18:48:43 +01:00
Miroslav Stampar
87ecf205cb
More work for Issue #66
2012-07-14 17:01:04 +02:00
Miroslav Stampar
58de90c118
Work for Issue #66
2012-07-14 16:53:15 +02:00
Miroslav Stampar
38d82771be
Minor style update
2012-07-14 11:23:22 +02:00
Miroslav Stampar
e9672056cd
Minor revert (returning that last \n)
2012-07-14 11:04:46 +02:00
Miroslav Stampar
805120ac52
Minor refactoring
2012-07-14 11:01:30 +02:00
Miroslav Stampar
3f4186ce2c
Removing duplicate user password hashes
2012-07-14 10:57:46 +02:00
Miroslav Stampar
9989d26174
Minor style update
2012-07-13 15:26:06 +02:00
Miroslav Stampar
9a7fc24ec2
Minor style update
2012-07-13 15:22:08 +02:00
Miroslav Stampar
ddb9caeef1
Revert of the previous commit
2012-07-13 15:05:19 +02:00
Miroslav Stampar
d165d5d5fe
To not be confused with heuristic method in SQLi
2012-07-13 15:03:43 +02:00
Miroslav Stampar
32b700f130
Minor style update
2012-07-13 15:02:11 +02:00
Miroslav Stampar
fbb5db00ba
Minor style update
2012-07-13 15:00:39 +02:00
Miroslav Stampar
786686da60
Minor language update
2012-07-13 14:53:42 +02:00
Miroslav Stampar
9ff9c951bc
Language update
2012-07-13 14:33:16 +02:00
Miroslav Stampar
6677da63cd
Fix for an Issue #88
2012-07-13 14:25:39 +02:00
Miroslav Stampar
3c81f74823
Minor style update
2012-07-13 12:22:37 +02:00
Miroslav Stampar
6ade007aec
Minor update of language
2012-07-13 12:13:04 +02:00
Miroslav Stampar
c5ecc8b8db
Closing work on Issue #83
2012-07-13 11:23:21 +02:00
Miroslav Stampar
48f68bd076
First commit for Issue #83
2012-07-13 10:35:22 +02:00
Miroslav Stampar
d834e8debf
Minor update
2012-07-13 10:28:03 +02:00
Miroslav Stampar
b11fd8b9f7
Fix for an Issue #87
2012-07-13 10:11:16 +02:00
Bernardo Damele
162da75a04
modified homepage address
2012-07-12 18:38:03 +01:00
Miroslav Stampar
a49d685eb8
Hidding --beep (Issue #84 )
2012-07-12 17:03:24 +02:00
Bernardo Damele
ea9c66108e
cleanup for issue #68
2012-07-12 15:38:43 +01:00
Miroslav Stampar
569c9214bf
Adding support for boldifying important logging messages
2012-07-12 16:30:35 +02:00
Miroslav Stampar
b2fe1c30f8
Minority report
2012-07-12 16:04:01 +02:00
Miroslav Stampar
8e18514e56
Minor refactoring for all that stickyness
2012-07-12 15:58:45 +02:00
Bernardo Damele
64143a146f
no need for bold error and critical messages, red is already enough
2012-07-12 14:54:05 +01:00
Miroslav Stampar
fe61bdce75
Minor update
2012-07-12 15:25:26 +02:00
Miroslav Stampar
dbbca16c69
Minor renaming
2012-07-12 15:24:40 +02:00
Miroslav Stampar
9bc24cea6b
Dealing with kb.currentMessage issue
2012-07-12 15:23:35 +02:00
Miroslav Stampar
b320dc118d
Minor fix (recognizing if it's colorizing handler or not)
2012-07-12 14:55:54 +02:00
Miroslav Stampar
cba2a26b68
Finishing Issue #75 (inference dumping)
2012-07-12 14:46:57 +02:00
Miroslav Stampar
65639cdda6
First update for Issue #75 (error-based dumping)
2012-07-12 14:31:28 +02:00
Miroslav Stampar
3fd5119f3f
Redesigning for Issue #75
2012-07-12 13:42:22 +02:00
Bernardo Damele
3d66e2dfb1
minor bug fix
2012-07-12 10:47:51 +01:00
Bernardo Damele
fed178646a
minor refactoring
2012-07-12 01:48:07 +01:00
Bernardo Damele
33cbbed4a8
I think we should not resume checkBooleanExpression() calls if --fresh-queries or --flush-session is provided
2012-07-12 01:39:15 +01:00
Bernardo Damele
f704a46341
silly blank line added
2012-07-12 01:38:29 +01:00
Bernardo Damele
01474f6272
proper debug message added - issue #75
2012-07-12 01:19:36 +01:00
Bernardo Damele
ee3aeb8dcf
actual implementation of issue #75 , still some work to do
2012-07-12 01:16:00 +01:00
Bernardo Damele
3a94953ae2
leftover from previous commit
2012-07-12 01:15:34 +01:00
Bernardo Damele
a5924739f6
minor code refactoring in preparation of ticket #75
2012-07-12 01:12:30 +01:00
Bernardo Damele
caeddf6822
avoid unescaping user provided queries (--sql-query, --sql-shell, --sql-file). Before it was only applied to --sql-file
2012-07-12 00:17:07 +01:00
Bernardo Damele
66d854c7d8
leftover space
2012-07-12 00:04:56 +01:00
Bernardo Damele
53c0336b48
added --hostname switch to retrieve DBMS server hostname - closes issue #69
2012-07-12 00:01:57 +01:00
Bernardo Damele
4e64c1126d
restored bold on questions to users (calls from readInput()) - issue #77
2012-07-11 22:56:11 +01:00
Bernardo Damele
247f95e051
restored kb.currentMessage - needed in cases where we send to dataToStdout() strings like "." (e.g. "creation in progres ..... done")
2012-07-11 22:48:27 +01:00
Bernardo Damele
2b3ea3e3b7
fixed colouring for PAYLOAD (-v 3) - issue #77
2012-07-11 22:40:52 +01:00
Bernardo Damele
44ad9bd0f6
removed unused commented lines
2012-07-11 22:40:05 +01:00
Miroslav Stampar
e673a57311
Fix for that ugly red blank line in CRITICAL messages
2012-07-11 20:49:22 +02:00
Miroslav Stampar
15ee5310d9
Adding traffic in and out to color_map
2012-07-11 20:42:18 +02:00
Miroslav Stampar
43cac2212b
Fix for a case when ColorizingStreamHandler is not used
2012-07-11 20:36:32 +02:00
Miroslav Stampar
72378d4f61
Some more refactoring
2012-07-11 20:29:48 +02:00
Miroslav Stampar
c6464b44be
Some more refactoring
2012-07-11 20:13:23 +02:00
Miroslav Stampar
d7926b8aac
Minor refactoring
2012-07-11 19:54:21 +02:00
Bernardo Damele
53ccd09ca4
now also readInput() uses colouring
2012-07-11 17:53:32 +01:00
Bernardo Damele
02ec25b4b8
code refactoring
2012-07-11 17:44:23 +01:00
Bernardo Damele
77b275f1a6
conf->kb
2012-07-11 17:32:12 +01:00
Bernardo Damele
1d2c87e24e
leftover
2012-07-11 17:22:01 +01:00
Bernardo Damele
105ac8ea77
deleted unnecessary hg file
2012-07-11 17:06:56 +01:00
Bernardo Damele
d987cd3ad0
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-07-11 17:05:01 +01:00
Bernardo Damele
015ea52284
added colorama library, BSD license, http://pypi.python.org/pypi/colorama
2012-07-11 17:04:52 +01:00
Bernardo Damele
79db97753b
slightly updated gitignore
2012-07-11 16:54:53 +01:00
Bernardo Damele
fa2f6f9a39
colourize manually crafter "logging" messages
2012-07-11 16:48:30 +01:00
Bernardo Damele
412ba5ca1a
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-07-11 16:45:29 +01:00
Bernardo Damele
9cfea57b10
added termcolor library, MIT license, http://pypi.python.org/pypi/termcolor
2012-07-11 16:45:18 +01:00
Miroslav Stampar
295a7a8e5e
Another update for Issue #80
2012-07-11 16:14:20 +02:00
Miroslav Stampar
9a4f8d5f45
Fix for Issue #80
2012-07-11 16:01:25 +02:00
Bernardo Damele
0702dd70b5
verify also that the web backdoor has been successfully uploaded
2012-07-11 14:08:51 +01:00
Bernardo Damele
6f6cd676b7
clean up the file system from sqlmap created web files
2012-07-11 14:07:20 +01:00
Bernardo Damele
0c5f259481
var renaming
2012-07-11 13:39:33 +01:00
Bernardo Damele
ff6ca6fb1a
colourize the whole log message
2012-07-11 12:18:48 +01:00
Bernardo Damele
31571e6e2d
minor refactoring
2012-07-11 11:55:05 +01:00
Miroslav Stampar
9c4a62f725
Some work on Issue #68
2012-07-11 11:58:47 +02:00
Bernardo Damele
115cd3479e
minor import fix
2012-07-10 13:13:21 +01:00
Bernardo Damele
f219b39980
minor fix in case ctypes is not installed on Windows
2012-07-10 13:08:37 +01:00
Miroslav Stampar
8caffac4bc
conf.unescape->kb.unescape
2012-07-10 10:55:04 +02:00
Miroslav Stampar
e7f78bf04f
Fix for an issue where False value was displayed for --is.. switches
2012-07-10 10:31:14 +02:00
Bernardo Damele
ea77e7d9d1
added missing file - issue #77
2012-07-10 03:00:21 +01:00
Bernardo Damele
43e58b63ea
modified debug colour - issue #77
2012-07-10 02:58:49 +01:00
Bernardo Damele
eb7ffb8f91
setup for implementing logging colouring - issue #77
2012-07-10 02:54:37 +01:00
Bernardo Damele
a14b7e6b6b
fixed the colors - issue #77
2012-07-10 02:47:35 +01:00
Bernardo Damele
4656d23d82
increased verbosity level of some messages and removed a leftover
2012-07-10 01:43:19 +01:00
Bernardo Damele
00b7411a87
more adjustments for issue #33 , of particular importance the fact that the user's provided statement from a file is never unescaped, should be ok
2012-07-10 01:39:03 +01:00
Bernardo Damele
0a3899858d
missed in previous commit
2012-07-10 01:37:53 +01:00
Bernardo Damele
a27f50ed1d
added conf.unescape global variable to control whether or not the injected statements should be unescaped
2012-07-10 01:37:16 +01:00
Bernardo Damele
f645ac6040
dealing with variables in SQL procs - issue #33
2012-07-10 01:05:03 +01:00
Bernardo Damele
2527554f8e
more work on #33
2012-07-10 00:53:07 +01:00
Bernardo Damele
c4af7b9aa0
initial work for issue #33
2012-07-10 00:27:08 +01:00
Bernardo Damele
d3da3f5c52
refactoring for issue #51
2012-07-10 00:19:32 +01:00
Bernardo Damele
25eca9d671
finally got this working on MSSQL 2005: commands can now be executed as another user (BULK INSERT must be used in such case, see comments in the code) - issue #34
2012-07-09 14:26:23 +01:00
Bernardo Damele
de33a128cb
added .sqlmap_history to files to ignore
2012-07-09 13:48:49 +01:00
Bernardo Damele
99c5ea54f7
cleanup for #34
2012-07-09 12:39:43 +01:00
Bernardo Damele
d08a54e375
properly display the command stdout
2012-07-09 10:52:48 +01:00
Miroslav Stampar
3ff28e58b4
Update regarding Issue #52
2012-07-08 19:24:25 +02:00
Miroslav Stampar
0d539a876d
Minor fix (subversion->github)
2012-07-07 23:49:34 +02:00
Miroslav Stampar
a525dd4336
Fix for Issue #72
2012-07-07 19:02:46 +02:00
Miroslav Stampar
54e0a2d8ee
--os-shell now works perfect for inference-like techniques too
2012-07-07 17:57:06 +02:00
Miroslav Stampar
823b3d8be8
Minor language fixes
2012-07-07 11:41:52 +02:00
Miroslav Stampar
2669528b24
Language typo
2012-07-07 11:16:33 +02:00
Miroslav Stampar
58f6687194
Some refactoring (reusing xpCmdshellForgeCmd)
2012-07-07 10:51:29 +02:00
Miroslav Stampar
8620767b77
Proper fix
2012-07-07 10:38:07 +02:00
Miroslav Stampar
f00a776d8d
Minor fix for BigArray (now accepting negative indexes)
2012-07-07 10:35:29 +02:00
Miroslav Stampar
1c69eb5d30
Revert "major fix"
...
This reverts commit 3a11fc2d9e .
2012-07-07 10:26:13 +02:00
Bernardo Damele
3a11fc2d9e
major fix
2012-07-06 22:55:34 +01:00
Miroslav Stampar
8c871476ee
Some more refactoring
2012-07-06 17:34:40 +02:00
Miroslav Stampar
86c27cc4f2
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-07-06 17:28:13 +02:00
Miroslav Stampar
6bc0b34031
Some more refactoring
2012-07-06 17:28:01 +02:00
Miroslav Stampar
e948e4d45b
Some more refactoring
2012-07-06 17:18:22 +02:00
Miroslav Stampar
1a8ebbfd43
Minor refactoring
2012-07-06 17:05:47 +02:00
Bernardo Damele
e673033ac1
minor layout adjustment
2012-07-06 15:26:45 +01:00
Bernardo Damele
fb7fe552b7
proper naming
2012-07-06 15:13:50 +01:00
Bernardo Damele
373fea03a3
fixed display of TABs
2012-07-06 15:13:23 +01:00
Miroslav Stampar
438a636973
Fix for issue Issue #60
2012-07-06 15:36:32 +02:00
Miroslav Stampar
76f7f907c6
Minor update for Issue #61
2012-07-06 14:33:40 +02:00
Miroslav Stampar
6a05e3fd79
Fix for Issue #61
2012-07-06 14:24:44 +02:00
Miroslav Stampar
1ebff35b19
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-07-06 12:25:21 +02:00
Miroslav Stampar
982fcde1c0
Fix for Issue #62
2012-07-06 12:24:55 +02:00
Bernardo Damele
4fa6d51d93
improved issues link
2012-07-05 16:26:50 +01:00
Miroslav Stampar
bc5025b06c
Fix for Issue #59
2012-07-05 12:34:27 +02:00
Miroslav Stampar
c3c1b9e957
Minor restyling
2012-07-04 20:28:18 +02:00
Miroslav Stampar
7ad6697446
Fix for Issue #57
2012-07-04 20:21:44 +02:00
Miroslav Stampar
23fb753759
Finishing work on Issue #52
2012-07-03 22:13:01 +02:00
Miroslav Stampar
40fc6488bf
Fix for Issue #56 (Google has changed few things for retrieving PR)
2012-07-03 21:00:18 +02:00
Miroslav Stampar
27fdccc858
Update for Issue #55 (falling back to SELECT DB_NAME(N))
2012-07-03 20:15:17 +02:00
Miroslav Stampar
bbf41f6658
Removing debugging leftover
2012-07-03 16:50:05 +02:00
Miroslav Stampar
ada627a022
Another update for Issue #52
2012-07-03 16:49:34 +02:00
Miroslav Stampar
70f754f6c5
Making work on Issue #52
2012-07-03 16:34:11 +02:00
Bernardo Damele
793fa464e3
website url fix
2012-07-03 13:14:39 +01:00
Miroslav Stampar
51f35674ca
Removing obsolete switch --version as version is now displayed with every run (Issue #54 )
2012-07-03 13:11:09 +02:00
Miroslav Stampar
481b46a004
Restyling output for Issue #52
2012-07-03 13:06:52 +02:00
Miroslav Stampar
6b419067b7
Another minor update for Issue #54
2012-07-03 12:49:35 +02:00
Miroslav Stampar
8b8677b938
Another minor update for Issue #54
2012-07-03 12:29:42 +02:00
Miroslav Stampar
47b6e696d8
Minor update for Issue #54
2012-07-03 12:21:40 +02:00
Miroslav Stampar
3af1532700
Implementation for Issue #54
2012-07-03 12:09:18 +02:00
Miroslav Stampar
5af6ca58a0
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-07-03 00:50:45 +02:00
Miroslav Stampar
168aeadf76
Adding switch --output-dir (Issue #53 )
2012-07-03 00:50:23 +02:00
Bernardo Damele
1bae9955b7
typo, #51
2012-07-02 15:31:25 +01:00
Bernardo Damele
cd769ba68f
minor adjustments, #51
2012-07-02 15:30:32 +01:00
Bernardo Damele
fd4cfb0cc0
working on #51
2012-07-02 15:28:19 +01:00
Bernardo Damele
7335072ab8
leftover
2012-07-02 15:11:21 +01:00
Bernardo Damele
04d803c7fd
more tweaking for issue #34 , it's totally not as trivial as it may look (OPENROWSET has many limitations on MSSQL >= 2005)
2012-07-02 15:02:00 +01:00
Bernardo Damele
b7d2680e55
minor refactoring, issue #51
2012-07-02 12:50:26 +01:00
Miroslav Stampar
8eefe4b71f
Getting back revision number - displayed like in GitHub commits (Issue #52 )
2012-07-02 13:01:20 +02:00
Bernardo Damele
add8352804
make the runAsDBMSUser() generic and ported to abstraction.py so the same function will be used for PostgreSQL dblink() too
2012-07-02 02:14:03 +01:00
Bernardo Damele
6697927098
initial support for --dbms-cred for MSSQL: can be used to execute OS commands as another DB use - useful if you have retrieved and cracked the 'sa' DBA password by any mean and can provide it to sqlmap
2012-07-02 02:04:19 +01:00
Bernardo Damele
87951bcff8
added output/ folder to the ignore list
2012-07-02 01:58:42 +01:00
Bernardo Damele
7b4ecd9df0
added skeleton code for issue #34 , still not usable
2012-07-02 00:22:34 +01:00
Bernardo Damele
4736d46677
just in case..
2012-07-02 00:00:46 +01:00
Bernardo Damele
03d2c9c818
placeholder message when --update is provided, remove when the function is updated to pull changes from git
2012-07-01 23:59:44 +01:00
Bernardo Damele
18be319d13
hexencoding the command is much shorter than unescaping with CHAR() for MSSQL, also no need for spaces between nested comments when forging the xp_cmdshell command to run
2012-07-01 23:41:10 +01:00
Bernardo Damele
ff9e97a42c
minor code refactoring
2012-07-01 23:31:45 +01:00
Bernardo Damele
ab412da27f
I am back on stage and here to stay!!! to start.. a removal of confirm switch which masked cases where file write operations failed when set to False automatically, now at least it asks the user and defaults to Yes
2012-07-01 23:25:05 +01:00
Miroslav Stampar
d7cd55fb28
Fix for Issue #47
2012-07-01 11:05:04 +02:00
Miroslav Stampar
21d9ae0a2c
some more refactoring
2012-07-01 01:19:54 +02:00
Miroslav Stampar
f6509db31a
minor refactoring
2012-07-01 00:33:19 +02:00
Miroslav Stampar
32f52cdd04
Another language update for Issue #45
2012-06-29 10:33:54 +02:00
Miroslav Stampar
f0e39c3fae
Language update for Issue #45
2012-06-29 10:33:00 +02:00
Miroslav Stampar
c0f16f0c1a
Fix for Issue #45
2012-06-29 10:31:03 +02:00
Miroslav Stampar
e51d3a02f1
Update for Issue #43 (renamed --disable-cracking to --disable-hash)
2012-06-28 18:53:47 +02:00
Miroslav Stampar
18b596ea75
Merge branch 'master' of github.com:sqlmapproject/sqlmap
2012-06-28 18:48:18 +02:00
Miroslav Stampar
c8bac658f3
Fix for Issue #43
2012-06-28 18:47:55 +02:00
Bernardo Damele
2551be121f
removed trailing newline
2012-06-28 14:31:30 +01:00
Miroslav Stampar
2a72fcce2b
Fix for Issue #42
2012-06-28 13:55:30 +02:00
Miroslav Stampar
f495cfa139
minor update
2012-06-27 23:32:16 +02:00
jekil
c39e5a85ba
Removed $id$ tags
2012-06-27 20:56:43 +02:00
Bernardo Damele
c0b9cf539f
moved udfhack to its own repository, https://github.com/sqlmapproject/udfhack
2012-06-27 15:15:11 +01:00
Bernardo Damele
19ff801d29
added .gitignore
2012-06-27 15:13:30 +01:00
Miroslav Stampar
1ebaeeb216
Syncing changes with those on gh-pages
2012-06-27 14:47:49 +02:00
Miroslav Stampar
303aa10507
only a small update
2012-06-27 14:43:18 +02:00
Bernardo Damele
4da2a3a8ac
minor adjustment to README file
2012-06-27 10:46:37 +01:00
Bernardo Damele
3af8e2302e
minor adjustment to README file
2012-06-27 10:43:38 +01:00
Bernardo Damele
72bba0c735
minor adjustment to README file
2012-06-27 10:42:42 +01:00
Bernardo Damele
17d6a62f4e
minor adjustment to README file
2012-06-27 10:41:52 +01:00
Bernardo Damele
2fc0f20d5e
minor adjustment to README file
2012-06-27 10:40:50 +01:00
Bernardo Damele
397b7758e3
minor adjustment to README file
2012-06-27 10:37:18 +01:00
Bernardo Damele
7780a76848
minor adjustment to README file
2012-06-27 10:15:39 +01:00
Bernardo Damele
1582f4cb17
added README file
2012-06-27 10:15:09 +01:00
Bernardo Damele
d6538985fc
added README file
2012-06-27 10:12:48 +01:00
Miroslav Stampar
eef2fc109a
test
2012-06-26 19:01:37 +02:00
inquisb
752c1632aa
Slight update to the user's manual following migration from Subversion to Git
2012-06-26 17:42:01 +01:00
Miroslav Stampar
1da6ae660c
adding a few more common tables
2012-06-25 16:39:36 +00:00
Miroslav Stampar
01be9381d5
minor update
2012-06-25 16:24:33 +00:00
Miroslav Stampar
6c4bd84d18
minor fix (turning back the functionality of kb.suppressResumeInfo)
2012-06-25 16:19:51 +00:00
Miroslav Stampar
ea5d483c86
session file no more
2012-06-21 11:19:30 +00:00
Miroslav Stampar
7dc4fc333f
making PHP stager smaller by 100 chars
2012-06-21 10:46:45 +00:00
Miroslav Stampar
ec44e88db8
lots of refactoring regarding removal of already obsolete session file mechanism
2012-06-21 10:09:10 +00:00
Miroslav Stampar
1e67b4f0b9
minor fix
2012-06-20 14:16:26 +00:00
Miroslav Stampar
302d782a0f
minor style update
2012-06-19 08:33:51 +00:00
Miroslav Stampar
452ef202ae
minor fixes
2012-06-17 22:48:23 +00:00
Miroslav Stampar
b9f6943a42
minor update
2012-06-17 21:23:12 +00:00
Miroslav Stampar
e2a60b302f
minor fix
2012-06-17 21:21:45 +00:00
Miroslav Stampar
3da8f86e97
minor fix
2012-06-15 21:01:27 +00:00
Miroslav Stampar
fe49abd45f
minor fix
2012-06-15 20:49:28 +00:00
Miroslav Stampar
06be7bbb18
few just in case fixes (unarrayizeValue in dumpTable entries) and and some refactoring (unique is now not done for every union case but only if detected that there are duplicates in union test)
2012-06-15 20:41:53 +00:00
Miroslav Stampar
76c873a222
minor fix
2012-06-15 06:22:44 +00:00
Miroslav Stampar
76584ff0fa
unhidding --test-filter
2012-06-14 14:36:53 +00:00
Miroslav Stampar
d2dd47fb23
some more refactoring
2012-06-14 13:52:56 +00:00
Miroslav Stampar
facce2c0df
some more cleanup
2012-06-14 13:50:36 +00:00
Miroslav Stampar
d5e80089ff
minor summer cleanup
2012-06-14 13:44:16 +00:00
Miroslav Stampar
3a90105fbb
minor refactoring
2012-06-14 13:38:53 +00:00
Miroslav Stampar
1204eb00b2
minor fix
2012-06-14 12:46:32 +00:00
Miroslav Stampar
19c0efec59
just a minor refactoring
2012-06-14 09:10:28 +00:00
Miroslav Stampar
a51d8c4c79
replacing identifier safe char " with [] enclosing for MsSQL
2012-06-13 15:27:42 +00:00
Miroslav Stampar
367de838c1
minor update
2012-06-13 14:08:32 +00:00
Miroslav Stampar
4ac3794e80
minor update
2012-06-12 14:22:14 +00:00
Miroslav Stampar
5d35d255ba
minor refactoring
2012-06-11 22:27:33 +00:00
Miroslav Stampar
d7f698fa14
minor update
2012-06-11 22:01:13 +00:00
Miroslav Stampar
96177393e1
minor update regarding --exact switch
2012-06-10 13:38:12 +00:00
Miroslav Stampar
b85a1fc271
minor fix
2012-06-05 22:55:42 +00:00
Miroslav Stampar
058a9c59a2
fix for a bug noticed in a multi target run (log files weren't saved properly - removed buffering as it didn't produce any noticeable results)
2012-06-05 22:40:55 +00:00
Miroslav Stampar
f94ebe3107
minor fix (credentials were only set for the first target)
2012-06-04 22:30:12 +00:00
Miroslav Stampar
738073105e
minor updates
2012-06-04 19:52:51 +00:00
Miroslav Stampar
7b282b1d6c
adding support for newer SSL protocols
2012-06-04 19:46:28 +00:00
Miroslav Stampar
10b0639a96
making a "--exact" switch on demand (choosing exact identifier names by default instead of LIKE)
2012-06-04 09:24:46 +00:00
Miroslav Stampar
76a4aa19ac
some more fine tunning
2012-05-28 19:50:12 +00:00
Miroslav Stampar
73dba249e8
one more just in case update
2012-05-28 19:34:47 +00:00
Miroslav Stampar
efb406fbfc
minor revert
2012-05-28 19:13:50 +00:00
Miroslav Stampar
f7cba8d2cb
minor update
2012-05-28 18:05:15 +00:00
Miroslav Stampar
a72cb29c1f
taking care of few issues regarding reverse address lookup of localhost/127.0.0.1 at remote DNS server
2012-05-28 16:57:10 +00:00
Miroslav Stampar
190ae4ca13
no need for conf.timeSec value as inference is always evaluated to False in DNS (large random values used for > ...)
2012-05-28 15:10:17 +00:00
Miroslav Stampar
89e90c3d84
revert of last commit
2012-05-28 15:01:56 +00:00
Miroslav Stampar
96c84e6e5b
minor update
2012-05-28 15:00:06 +00:00
Miroslav Stampar
a70a647aeb
few fixes regarding --dns-domain usage (time-based technique should not be used as a failback because of few things, --time-sec should be put to 0 just in case,...)
2012-05-28 14:51:23 +00:00
Miroslav Stampar
b1d82422a0
changing conf.dnsDomain to conf.dName just because of long text problems in help listing
2012-05-28 14:15:04 +00:00
Miroslav Stampar
d2bbfa4aad
minor style update
2012-05-28 14:04:17 +00:00
Miroslav Stampar
226547b7dc
minor fix for --skip-urlencode and custom post
2012-05-28 09:04:25 +00:00
Miroslav Stampar
75dd1d6a2b
minor fix
2012-05-27 21:54:56 +00:00
Miroslav Stampar
e967bbd70f
minor patch
2012-05-27 21:44:42 +00:00
Miroslav Stampar
76eeba10e2
unhiding --dns-domain switch
2012-05-27 18:41:06 +00:00
Miroslav Stampar
fed0212631
now working with recursive queries too
2012-05-27 10:03:02 +00:00
Miroslav Stampar
71ff081fde
minor update
2012-05-27 09:11:19 +00:00
Miroslav Stampar
09f2144485
full page read is not needed in DNS exfiltration mode
2012-05-26 21:28:43 +00:00
Miroslav Stampar
4e6fcce9ca
minor update
2012-05-26 07:04:32 +00:00
Miroslav Stampar
ce077137c9
minor language update
2012-05-26 07:01:37 +00:00
Miroslav Stampar
d335ec0c34
turning back on time auto-adjustment mechanism (if turned off) after a threshold run of valid chars
2012-05-26 07:00:26 +00:00
Miroslav Stampar
00d22f013f
some consistency in variable naming at the file level
2012-05-25 10:08:55 +00:00
Miroslav Stampar
db526bdbc0
minor update (tainted values are not checked any more in multipleTargets mode)
2012-05-25 09:52:17 +00:00
Miroslav Stampar
dc20bff1d0
minor update
2012-05-25 08:30:24 +00:00
Miroslav Stampar
c394610740
adding switch --skip-urlencode to skip URL encoding of POST data
2012-05-24 23:30:33 +00:00
Miroslav Stampar
7657bbeaf9
minor update
2012-05-24 22:32:06 +00:00
Miroslav Stampar
86fdad2bfa
minor update
2012-05-24 22:07:50 +00:00
Miroslav Stampar
eed8d7eb5d
finalizing support for IPv6
2012-05-24 21:55:57 +00:00
Miroslav Stampar
b6d37d766a
minor update regarding IPv6 support
2012-05-24 21:49:20 +00:00
Miroslav Stampar
92286104e3
minor just in case update
2012-05-24 21:39:10 +00:00
Miroslav Stampar
3e9c57d177
minor fix
2012-05-24 21:36:35 +00:00
Miroslav Stampar
be76928293
minor fix
2012-05-24 20:53:01 +00:00
Miroslav Stampar
3f6bc1f3c2
minor fix
2012-05-24 18:05:33 +00:00
Miroslav Stampar
1e18168cc8
fix for one silent bug and small language update
2012-05-23 16:35:40 +00:00
Miroslav Stampar
2538e2d5b4
fixing an issue with --file-read and ROW() MySQL payload (it's internal caching mechanism prevents error message if FROM part is not unique enough dumping only partial file content); minor refactoring
2012-05-22 09:33:22 +00:00
Miroslav Stampar
2c057d5b3d
minor style update
2012-05-21 22:40:52 +00:00
Miroslav Stampar
3a9e266d78
adding revisited wildcard LIKE payloads
2012-05-21 21:49:54 +00:00
Miroslav Stampar
602369c762
reverting last changes on boundaries
2012-05-21 09:20:46 +00:00
Miroslav Stampar
588d829be6
update of doc/THANKS
2012-05-21 08:34:12 +00:00
Miroslav Stampar
1500b3fccd
adding a new payload boundaries by smcintyre@securestate.com
2012-05-21 08:31:37 +00:00
Miroslav Stampar
0e8d8577a7
adding a DB2 patch from smcintyre@securestate.com
2012-05-21 08:26:19 +00:00
Miroslav Stampar
079e0e1434
minor bug fix
2012-05-18 08:51:50 +00:00
Miroslav Stampar
bbfa4b6d5d
minor update
2012-05-14 14:38:16 +00:00
Miroslav Stampar
333f8057a5
minor fix (when redirected path has non-ASCII char and conf.url is unicode) and bits along with pieces
2012-05-14 14:06:43 +00:00
Miroslav Stampar
595f69fa2c
minor language update
2012-05-10 18:30:25 +00:00
Miroslav Stampar
35f400b45b
minor language upgrade
2012-05-10 18:25:12 +00:00
Miroslav Stampar
80aedbe284
adding a warning about --tor switch
2012-05-10 18:17:32 +00:00
Miroslav Stampar
b81fe42d4b
turning off null connection on -o when --tor used (not compatible)
2012-05-10 17:50:54 +00:00
Miroslav Stampar
efdd86ddcc
minor just in case patch
2012-05-10 14:22:34 +00:00
Miroslav Stampar
6367f59b98
minor code refactoring
2012-05-10 14:15:17 +00:00
Miroslav Stampar
12d32f58f2
fix for that SOAP reported bug
2012-05-10 13:39:54 +00:00
Miroslav Stampar
1418ae9767
little refactoring of parseUnionPage together with a patch for some special case
2012-05-09 18:47:40 +00:00
Miroslav Stampar
7fb1f3fc70
minor renaming
2012-05-09 18:26:02 +00:00
Miroslav Stampar
11d9859199
making nice code
2012-05-09 18:25:04 +00:00
Miroslav Stampar
b0a8238774
minor fixes
2012-05-09 14:58:16 +00:00
Miroslav Stampar
9fa3619262
minor fix
2012-05-09 14:00:07 +00:00
Miroslav Stampar
56a3431be6
minor update for empty tables (skipping other techniques)
2012-05-09 10:34:21 +00:00
Miroslav Stampar
6177317a17
minor update
2012-05-09 10:06:23 +00:00
Miroslav Stampar
37f2709197
making a generic solution for all "Generic comment"/MsAccess cases (it's the only DBMS which doesn't accept --, hence replacing generic comment with %00 for it)
2012-05-09 09:08:23 +00:00
Miroslav Stampar
fdf61015ad
minor patch
2012-05-09 08:41:05 +00:00
Miroslav Stampar
e419177871
minor update
2012-05-08 17:28:19 +00:00
Miroslav Stampar
deec97dfe3
adding Frontbase to error message regexes
2012-05-08 17:02:58 +00:00
Miroslav Stampar
eccd4da00f
minor fix
2012-05-08 15:03:33 +00:00
Miroslav Stampar
938d9ff23e
doing all the work for the users so they wouldn't strain their little hands
2012-05-08 15:00:23 +00:00
Miroslav Stampar
524dd75ff2
that query variable hasn't been used anywhere (obsolete for some time)
2012-05-08 14:34:40 +00:00
Miroslav Stampar
6af110d631
avoiding --no-cast/--hex warning message before a DBMS is fingerprinted
2012-05-08 14:06:41 +00:00
Miroslav Stampar
64c241fe92
limiting original UNION query results to only 1 result (potentially speeding things up in some cases)
2012-05-08 13:45:53 +00:00
Miroslav Stampar
e00f4a8934
minor cosmetics
2012-05-08 10:50:04 +00:00
Miroslav Stampar
a121339395
automatically writing uncracked hashes to a file for eventual further processing
2012-05-08 10:46:05 +00:00
Miroslav Stampar
80ee687b41
minor beauty patch
2012-05-07 13:51:31 +00:00
Miroslav Stampar
e9f6b00e26
minor fix in a KeepAlive library
2012-05-07 13:36:36 +00:00
Miroslav Stampar
57234e1ff5
fix for proper (international character) inference on MsAccess
2012-05-03 23:13:48 +00:00
Miroslav Stampar
96299d3d5d
minor refactoring
2012-05-03 22:34:18 +00:00
Miroslav Stampar
cc28f6db6b
minor update
2012-05-01 20:43:16 +00:00
Miroslav Stampar
8013a64f8c
minor refactoring
2012-05-01 19:57:30 +00:00
Miroslav Stampar
c71d435d9f
making "id"-like columns prioritized for ORDER BY in MySQL
2012-05-01 19:52:02 +00:00
Miroslav Stampar
17efeaae7f
causing too much confusion among dummy users
2012-05-01 09:04:11 +00:00
Miroslav Stampar
458a73c9b4
few consistency fixes
2012-04-29 23:09:00 +00:00
Miroslav Stampar
694b14111f
skipping suffix if comment is used in agent.suffixQuery (and --suffix not explicitly set)
2012-04-27 13:16:51 +00:00
Miroslav Stampar
c7a606637f
switching few readInput defaults for brute forcing when no table/column found
2012-04-27 12:59:22 +00:00
Miroslav Stampar
1e45ee9ab6
reverting back to smaller UNION ranges as that mechanism for automatic extending was implemented few days ago
2012-04-25 20:37:39 +00:00
Miroslav Stampar
6f67dc85ee
adding --invalid-bignum (Havij like bignum style for invalidating/negating values); renaming --logical-negate to --invalid-logical
2012-04-25 20:29:07 +00:00
Bernardo Damele
4da03d898e
Added support to create files with a visual basic script - no longer reliant on debug.exe so works on Windows 64-bit too. Fixes #236
2012-04-25 07:40:42 +00:00
Bernardo Damele
6116853025
Minor layout adjustments
2012-04-24 17:01:24 +00:00
Miroslav Stampar
cec432f94d
minor update
2012-04-23 14:43:59 +00:00
Miroslav Stampar
697768c01a
adding --purge-output to be one of mandatory switches
2012-04-23 14:42:24 +00:00
Miroslav Stampar
d57d5e4b2c
minor update
2012-04-23 14:33:36 +00:00
Miroslav Stampar
1eecfb3dce
adding new file related to the last commit
2012-04-23 14:25:16 +00:00
Miroslav Stampar
095b25e1d1
adding option '--purge'
2012-04-23 14:24:23 +00:00
Miroslav Stampar
3532d23933
automatically extending ranges for UNION tests in case where at least one other injection technique is usable (boundaries has been established)
2012-04-23 13:41:36 +00:00
Bernardo Damele
eb73cab636
increased UNION test ranges
2012-04-23 11:54:52 +00:00
Miroslav Stampar
be2da77bf8
minor update
2012-04-23 10:15:04 +00:00
Miroslav Stampar
21c6b52198
minor fix
2012-04-23 10:11:00 +00:00
Miroslav Stampar
775134639d
minor update
2012-04-20 20:33:15 +00:00
Bernardo Damele
072e08836f
Falling back to unionReadFile() when --file-read does not work against MySQL. This happens when the session user does not have INSERT privilege, required to run LOAD DATA INFILE
2012-04-19 14:05:45 +00:00
Miroslav Stampar
2b1b4c0742
minor fix
2012-04-18 10:01:04 +00:00
Miroslav Stampar
6ebb621228
adding support for (custom) POST injection (marking injection point with '*' in conf.data)
2012-04-17 14:23:00 +00:00
Miroslav Stampar
efd27d7ade
minor renaming
2012-04-17 08:41:19 +00:00
Miroslav Stampar
ccd6fb70a8
minor refactoring
2012-04-15 17:17:30 +00:00
Miroslav Stampar
965c1511a6
adding new tamper script
2012-04-15 17:10:43 +00:00
Miroslav Stampar
601d118c68
reverting back to UNION ALL scheme (UNION is doing another DISTINCT on data causing problems on some column types)
2012-04-15 16:59:03 +00:00
Miroslav Stampar
71b0acc16f
minor fix (checking for full inband should be done with ORIGINAL - more concise)
2012-04-15 16:43:18 +00:00
Miroslav Stampar
5772c52f46
minor refactoring/fix (randQuery is just a part (e.g. abc) of phrase (def:abc:ghi) - phrase should be searched for, not just randQuery); both phrases should be inside the content for it to be full-inband injectable (...UNION ALL SELECT phrase UNION ALL SELECT phrase2....)
2012-04-15 16:33:47 +00:00
Miroslav Stampar
ae8c70e895
another cosmetics
2012-04-13 15:11:44 +00:00
Miroslav Stampar
d765cdc3a3
minor cosmetics
2012-04-13 15:10:40 +00:00
Miroslav Stampar
54576ab3a6
making a random choice from candidates
2012-04-13 10:54:30 +00:00
Miroslav Stampar
bbbcc95fe5
use it only if page is stable
2012-04-13 10:19:26 +00:00
Miroslav Stampar
414c74b8aa
new payload
2012-04-13 08:16:33 +00:00
Miroslav Stampar
052d9455fe
warning user in cases of "User xyz already has more than 'max_user_connections' active connections"
2012-04-12 09:44:54 +00:00
Miroslav Stampar
831f79b851
minor generalization
2012-04-12 09:30:19 +00:00
Miroslav Stampar
c7422546e1
tiny update
2012-04-11 23:01:38 +00:00
Miroslav Stampar
2bad73a981
minor update
2012-04-11 21:48:44 +00:00
Miroslav Stampar
e195de2093
correcting comment on reflective removal function
2012-04-11 21:41:48 +00:00
Miroslav Stampar
b45ae10da4
minor fixes
2012-04-11 21:36:37 +00:00
Miroslav Stampar
627bfc589f
some more updates in reflective removal mechanism
2012-04-11 21:26:00 +00:00
Miroslav Stampar
8b130f6497
minor improvement for reflective values (when missing first part of payload like in error reports)
2012-04-11 15:01:28 +00:00
Miroslav Stampar
01bd5d0ab2
some more updates for reflective mechanism
2012-04-11 10:41:33 +00:00
Miroslav Stampar
2e92d8636e
improvement of reflective mechanism
2012-04-11 08:58:03 +00:00
Miroslav Stampar
60ca44e0cf
minor adjustment
2012-04-11 08:35:09 +00:00
Miroslav Stampar
e33ea7c33a
minor fix
2012-04-10 22:29:39 +00:00
Miroslav Stampar
8541222080
minor update
2012-04-10 22:26:42 +00:00
Miroslav Stampar
9c2f244d47
minor fix
2012-04-10 22:20:53 +00:00
Miroslav Stampar
a82206cec4
minor cosmetics
2012-04-10 21:57:00 +00:00
Miroslav Stampar
119eec3598
improving "boolean detection" by automatic recognition of convenient --string candidate
2012-04-10 21:48:34 +00:00
Miroslav Stampar
698b7a15d9
minor update
2012-04-07 14:14:26 +00:00
Miroslav Stampar
8c6eb4faa9
adding support for PgSQL DNS data exfiltration
2012-04-07 14:06:11 +00:00
Miroslav Stampar
b2afa87e48
reading page responses in chunks, trimming unnecessary content (especially for large table dumps in full inband cases)
2012-04-06 08:42:36 +00:00
Miroslav Stampar
2223c884e5
minor refactoring
2012-04-05 12:55:26 +00:00
Miroslav Stampar
02924eb345
minor update
2012-04-04 23:47:06 +00:00
Miroslav Stampar
e0994947e2
minor update
2012-04-04 23:37:50 +00:00
Miroslav Stampar
b1dd03731a
minor cosmetics
2012-04-04 23:34:08 +00:00
Miroslav Stampar
83387d92bb
minor bug fix
2012-04-04 23:32:20 +00:00
Miroslav Stampar
c89a4162e2
bug fix for --dns-domain with --technique=TS
2012-04-04 18:01:39 +00:00
Bernardo Damele
80228f67f6
removed newline
2012-04-04 13:49:03 +00:00
Bernardo Damele
e23efabf86
removed unuseful spaces
2012-04-04 13:36:18 +00:00
Bernardo Damele
c051d7fecc
Prefer xp_dirtree
2012-04-04 13:29:25 +00:00
Miroslav Stampar
098c7c06dd
added few comments
2012-04-04 13:24:58 +00:00
Miroslav Stampar
a5b69eaea4
removing unused imports
2012-04-04 13:18:14 +00:00
Bernardo Damele
52796bb4da
revert
2012-04-04 13:02:50 +00:00
Miroslav Stampar
a4b95ab7dd
works against MySQL/Windows
2012-04-04 12:49:45 +00:00
Bernardo Damele
a1d97e9d7b
Add a space after a comment
2012-04-04 12:48:21 +00:00
Bernardo Damele
025c531d22
leftover
2012-04-04 12:44:25 +00:00
Bernardo Damele
c0946ce2c9
Minor refactoring
2012-04-04 12:42:58 +00:00
Bernardo Damele
75d1dab895
more cosmetics
2012-04-04 12:33:16 +00:00
Bernardo Damele
d106fb5184
layout adjustments
2012-04-04 12:27:24 +00:00
Miroslav Stampar
1b2cd44255
proper fix
2012-04-04 10:35:52 +00:00
Miroslav Stampar
7031ef8e00
removing default values for referer and host from higher level/risk options
2012-04-04 10:34:27 +00:00
Bernardo Damele
1f82d29a36
switch two conditional payloads for proper detection
2012-04-04 10:11:48 +00:00
Miroslav Stampar
5e358b51f9
few fixes related to bug report by Shadow Folder (AttributeError: 'list' object has no attribute 'isdigit')
2012-04-04 09:25:05 +00:00
Bernardo Damele
d5b4b7996a
minor revert
2012-04-04 00:09:47 +00:00
Bernardo Damele
049c27c739
improved detection for INSERT and UPDATE statements
2012-04-03 23:29:06 +00:00
Miroslav Stampar
11546cdb6e
minor refactoring
2012-04-03 19:09:35 +00:00
Miroslav Stampar
5851badff1
minor refactoring
2012-04-03 14:46:09 +00:00
Miroslav Stampar
b0787f193c
getting rid of obsolete getCompiledRegex (in newer versions of Python regexes are already cached)
2012-04-03 14:34:15 +00:00
Miroslav Stampar
556b349be3
minor fix for retrieving non-printable chars in inference and non-multi threading mode
2012-04-03 14:04:07 +00:00
Miroslav Stampar
33bb9c5f19
much cleaner approach in that "flat" representation of retrieved items in union technique
2012-04-03 13:56:11 +00:00
Miroslav Stampar
7fb190f3b1
minor fix
2012-04-03 12:35:19 +00:00
Miroslav Stampar
886aa22efc
minor update
2012-04-03 12:19:37 +00:00
Miroslav Stampar
503988887c
minor update
2012-04-03 10:43:46 +00:00
Miroslav Stampar
78f51fd2e5
minor fix
2012-04-03 10:18:03 +00:00
Miroslav Stampar
2504f4edb8
minor fixes
2012-04-03 10:10:33 +00:00
Miroslav Stampar
e05109812f
minor improvements regarding data retrieval through DNS channel
2012-04-03 09:18:30 +00:00
Miroslav Stampar
46cfa64d81
minor update
2012-04-02 21:06:57 +00:00
Miroslav Stampar
5f94987b0f
fix for DNS method for MSSQL
2012-04-02 17:28:18 +00:00
Miroslav Stampar
2c28423cb8
minor update
2012-04-02 14:57:15 +00:00
Miroslav Stampar
8a9d09f79b
minor fixes
2012-04-02 14:11:23 +00:00
Miroslav Stampar
1cd3c3f7af
further update of DNS data retrieval mechanism through SQLi
2012-04-02 14:05:30 +00:00
Miroslav Stampar
1e01203562
few just in case "patches"
2012-04-02 12:58:10 +00:00
Miroslav Stampar
d908d078dd
minor fix
2012-04-02 12:27:30 +00:00
Miroslav Stampar
abffc39929
minor update regarding DNS data retrieval task
2012-04-02 12:22:40 +00:00
Miroslav Stampar
f7a664b120
enablind DNS server for DNS data exfiltration
2012-03-31 12:08:27 +00:00
Miroslav Stampar
8be9cd4ac4
bug fix (on Linux machine when os.geteuid() returns an integer value !=0 it was then returned and interpreted as TRUE value)
2012-03-31 10:22:50 +00:00
Bernardo Damele
40a7232de6
Minor fix to avoid useless tests (FROM DUAL is Oracle specific so no point using + to concatenate strings)
2012-03-30 16:27:08 +00:00
Miroslav Stampar
429b8396e9
minor update for DNSServer support
2012-03-30 13:20:29 +00:00
Miroslav Stampar
56638f9e95
making --no-cast unhidden and renaming --negative-logic to --logical-negate to prevent confusion with stuff used in OR boolean based injection
2012-03-30 10:50:01 +00:00
Miroslav Stampar
79c3d6f2aa
minor update
2012-03-30 10:37:46 +00:00
Miroslav Stampar
6acf6b193a
minor update regarding boolean logic comparison mechanism
2012-03-30 09:42:58 +00:00
Miroslav Stampar
5469186540
minor comment update
2012-03-29 14:35:47 +00:00
Miroslav Stampar
637a8d8273
improvement toward proper implementation of OR-based injection by usage of "negative logic" mechanism
2012-03-29 14:33:27 +00:00
Miroslav Stampar
ce4c697bbd
disabling "negative logic" as it's not half done (it was "luckily" working for --string/--regex/--code but it was a sheer luck); removing "dirty fix" from checks.py; proof that this was not ready for the release is that there was not check for negative logic anywhere for anything more then --string/--regex/--code
2012-03-29 13:39:12 +00:00
Miroslav Stampar
772ead8d03
fixed support for error-based injection on MySQL 4.1 (help table a needs more than 2 items inside); also, fixed some border issues with reflective values
2012-03-29 12:44:20 +00:00
Miroslav Stampar
c9cac957bb
adding one more case for false positive check (Generic tests without any DBMS knowledge)
2012-03-29 09:56:09 +00:00
Miroslav Stampar
60146481af
bug fix(es) (flags were used in place of count parameter in re.sub() calls)
2012-03-28 19:33:00 +00:00
Miroslav Stampar
9433bbe26d
memory optimization for reflective removal mechanism (there was no need for \n\r in the first place as there was no re.S flag used - also, one re.sub "flags <-> count" bug fixed)
2012-03-28 19:27:12 +00:00
Miroslav Stampar
7d131d1fb1
minor update
2012-03-28 13:46:31 +00:00
Miroslav Stampar
7fd64df167
minor code cleaning
2012-03-28 13:31:07 +00:00
Miroslav Stampar
769b0d0ae7
more minor updates regarding data retrieval through DNS channel
2012-03-27 19:29:24 +00:00
Miroslav Stampar
9199ce5054
minor update
2012-03-27 19:07:17 +00:00
Miroslav Stampar
1b072f6415
laying foundation for DNS based data retrieval
2012-03-27 18:59:12 +00:00
Miroslav Stampar
645fc8a21c
minor refactoring
2012-03-27 08:31:48 +00:00
Miroslav Stampar
3abcd6910a
strange combination of "Set-Cookie" and interleaved pattern of True/False like responses can result in bypassing of the ABAB test
2012-03-22 00:06:50 +00:00
Miroslav Stampar
e88687b1f0
revert of last commit (it would be faster for sure, but not sure if it's clever to do it by default regarding SQLi detection)
2012-03-21 23:15:59 +00:00
Miroslav Stampar
524c1d38ad
making default redirect choice to NO (making fewer requests by default and in lots of cases clearer pages for comparison - original page vs redirect message)
2012-03-21 23:03:57 +00:00
Miroslav Stampar
11132ba993
fix for a bug in reflection removal mechanism
2012-03-19 14:28:18 +00:00
Miroslav Stampar
8e7d360ea2
cleaner refactoring regarding last commit
2012-03-19 12:03:25 +00:00
Miroslav Stampar
401763b6f8
minor fix (it has to be level 1 array like it was with the previous re.findall mechanism)
2012-03-19 12:00:22 +00:00
Miroslav Stampar
72c5b034bf
minor update
2012-03-19 11:50:38 +00:00
Miroslav Stampar
cb8caf7e0f
i am not very bright today :)
2012-03-19 11:23:23 +00:00
Miroslav Stampar
d5915e5d44
one other fix
2012-03-19 11:19:26 +00:00
Miroslav Stampar
7abfa2e6d4
minor fix
2012-03-19 11:18:00 +00:00
Miroslav Stampar
cce5c3c009
minor changes for version numbers
2012-03-19 11:07:03 +00:00
Miroslav Stampar
037db9b3b8
minor removal of older stuff
2012-03-19 09:38:27 +00:00
Miroslav Stampar
da7f4eeffd
removing left over
2012-03-18 17:33:14 +00:00
Miroslav Stampar
0fc4288a7c
modifying redirection code for only two choices
2012-03-18 17:27:08 +00:00
Bernardo Damele
c03d0e24fb
it must stay as is
2012-03-16 17:42:00 +00:00
Bernardo Damele
3505503a08
no need to return here
2012-03-16 17:30:16 +00:00
Bernardo Damele
942d9e4fa8
code cleanup
2012-03-16 17:27:24 +00:00
Bernardo Damele
a1c943fc79
Major bug fix to comparison algorithm with OR based boolean-based injections
2012-03-16 17:22:55 +00:00
Miroslav Stampar
d66056fe39
one more related commit
2012-03-16 13:16:53 +00:00
Miroslav Stampar
ac02a2d92c
minor fix
2012-03-16 13:14:14 +00:00
Miroslav Stampar
cbdcbdd786
minor minor update
2012-03-16 11:18:18 +00:00
Miroslav Stampar
b130a9e14e
minor fix (writing to HashDB on any interrupt)
2012-03-16 10:15:43 +00:00
Miroslav Stampar
577caac4de
putting kb.negativeLogic setting to the safe place
2012-03-16 09:17:11 +00:00
Miroslav Stampar
209e795369
minor just in case update
2012-03-16 09:02:17 +00:00
Miroslav Stampar
adb5fff6b2
one more update related to the redirection mechanism
2012-03-15 20:17:40 +00:00
Miroslav Stampar
7d313ac911
few more fixes for proper redirecting mechanism
2012-03-15 19:47:59 +00:00
Bernardo Damele
48e8c978fb
Minor fix, way more to do for --search -C for MSSQL
2012-03-15 17:55:49 +00:00
Bernardo Damele
86c4650058
Minor bug fix - revert
2012-03-15 17:12:24 +00:00
Bernardo Damele
cc15373769
More explicit function name also getRatioValue parameter has nothing to do with comparison at this stage as far as I can see (that might have fixed another "bug", to be checked later)
2012-03-15 16:29:28 +00:00
Bernardo Damele
4520744b4d
second step toward negative logic support (ported to detection phase too) - works well with --string, --regexp and --code now
2012-03-15 16:25:26 +00:00
Bernardo Damele
0013b0970f
Minor layout adjustments - foundDb is misleading at that stage
2012-03-15 16:07:16 +00:00
Miroslav Stampar
ddd92476a8
minor fix
2012-03-15 15:58:25 +00:00
Miroslav Stampar
19beb912fa
first step toward negative logic support
2012-03-15 15:52:12 +00:00
Miroslav Stampar
8dd570057b
minor fix (double traffic log for -t in case of HTTP error)
2012-03-15 14:51:16 +00:00
Miroslav Stampar
f7df755f37
minor update
2012-03-15 12:55:22 +00:00
Miroslav Stampar
3d39c6cb3b
some fixes here and there
2012-03-15 12:14:50 +00:00
Miroslav Stampar
3d9b1599d1
minor update
2012-03-15 11:45:32 +00:00
Miroslav Stampar
91f1d6141f
minor fix
2012-03-15 11:24:55 +00:00
Miroslav Stampar
a8c9a47092
redirect logic rewritten from scratch
2012-03-15 11:10:58 +00:00
Miroslav Stampar
84479eebe9
minor fix
2012-03-15 08:55:42 +00:00
Bernardo Damele
890bf708bc
Minor fixes to make --os-* switch work again against MySQL/Windows/ASP.NET (where stacked queries are supported)
2012-03-15 00:19:57 +00:00
Miroslav Stampar
8cf5d260fd
Application Data is not a temporary directory writable by everybody
2012-03-14 23:44:29 +00:00
Bernardo Damele
1e71b24dca
More info messages to prove xp_cmdshell (and temporary directory choosen) worked
2012-03-14 22:41:53 +00:00
Bernardo Damele
c735d846ee
The default temporary directory as to stay as is, do not touch this code snippet anymore please
2012-03-14 22:39:46 +00:00
Miroslav Stampar
52a8b25ff4
minor fix
2012-03-14 14:31:41 +00:00
Miroslav Stampar
ca0d068575
distinguishing NULL from BLANK
2012-03-14 13:52:23 +00:00
Miroslav Stampar
e38b59a2ae
minor update
2012-03-14 13:16:49 +00:00
Miroslav Stampar
cee9ff7885
proper parsing of content in partial union technique
2012-03-14 11:23:30 +00:00
Miroslav Stampar
61ad3b999a
fix for a crash with partial union and --hex
2012-03-14 10:31:24 +00:00
Miroslav Stampar
a7fbc55748
grammar fix
2012-03-13 22:03:23 +00:00
Miroslav Stampar
edfcddd3c3
minor fix for logging only cookies used by request (e.g. --load-cookies case)
2012-03-13 10:58:15 +00:00
Miroslav Stampar
34b0935cb3
refactoring "echo 1" quick test for xp_cmdshell console output
2012-03-13 10:36:49 +00:00
Miroslav Stampar
e827f41cdb
using pickle HIGHEST_PROTOCOL just in case
2012-03-13 09:35:37 +00:00
Miroslav Stampar
e6c610abab
minor fix
2012-03-13 09:14:56 +00:00
Miroslav Stampar
cda8815634
introducing safe deprecation mechanism for HashDB versioning
2012-03-12 22:55:57 +00:00
Miroslav Stampar
48bcde478e
more general update
2012-03-12 15:29:55 +00:00
Miroslav Stampar
1d0c8a7f44
minor update
2012-03-12 15:19:02 +00:00
Miroslav Stampar
6ed1b04bbe
minor update
2012-03-12 13:27:07 +00:00
Bernardo Damele
48592f2515
minor adjustments
2012-03-09 18:34:18 +00:00
Bernardo Damele
be9b103b51
minor bug fix
2012-03-09 18:02:50 +00:00
Bernardo Damele
012fc21b49
Improvements to column(s) search: now it's possible to search column(s) in provided table(s) across all databases, search column(s) across all tables in provided database(s) or let sqlmap alone identify the databases' tables - this is now implemented for error-based, union query and direct connection. Work is still required for boolean-based and time-based.
...
Adapted the queries.xml file accordingly
2012-03-09 17:47:50 +00:00
Miroslav Stampar
c878dd3e5a
doing a dummy test for --os-shell in case of xp_cmdshell
2012-03-09 14:21:41 +00:00
Bernardo Damele
4ac2611a56
Added another tamper script
2012-03-09 12:09:19 +00:00
Bernardo Damele
d9e499af9f
Set Id property
2012-03-09 12:05:21 +00:00
Miroslav Stampar
a0b46963cb
minor fix for some special "unusable" cases (seen on Access/ODBC/Linux setup)
2012-03-09 10:28:19 +00:00
Bernardo Damele
7330dff255
Minor bug fix for --search -C so that now if not columns are found (with criteria specified, e.g. -D testdb -T testtable), it won't ask to dump for the entries
2012-03-08 16:57:53 +00:00
Miroslav Stampar
e678219a8c
minor update
2012-03-08 15:51:30 +00:00
Bernardo Damele
ae87df5670
leftover
2012-03-08 15:45:33 +00:00
Miroslav Stampar
5a83f1c5f7
minor update
2012-03-08 15:43:22 +00:00
Bernardo Damele
4bc6f3f6c9
Minor bug fix so that --search -T tablename -D db1,db2 now correctly forges the query concatenating db1 and db2 with a OR, not an AND anymore
2012-03-08 15:32:05 +00:00
Miroslav Stampar
68b9d48d0a
minor update
2012-03-08 15:30:23 +00:00
Miroslav Stampar
2ab80bfb2c
minor bug fix
2012-03-08 15:24:05 +00:00
Bernardo Damele
c79807f5fb
Minor layout adjustments
2012-03-08 15:11:24 +00:00
Miroslav Stampar
775e424bf2
bug fix for using --no-cast and --hex switches together
2012-03-08 15:04:52 +00:00
Miroslav Stampar
11c7cc5224
minor temporary fix
2012-03-08 11:08:43 +00:00
Miroslav Stampar
98a3e43f53
bug fix for writing raw pickled data into SQLite HashDB
2012-03-08 10:57:47 +00:00
Miroslav Stampar
cd28eb6544
minor update regarding --load-cookies
2012-03-08 10:19:34 +00:00
Miroslav Stampar
2c87d061e9
minor update
2012-03-08 10:03:59 +00:00
Miroslav Stampar
9ca8bc4d51
minor bug fix
2012-03-08 09:52:33 +00:00
Miroslav Stampar
b4cf8b05b3
added switch --load-cookies
2012-03-07 14:48:45 +00:00
Miroslav Stampar
4cfea96471
minor update
2012-03-05 09:56:48 +00:00
Miroslav Stampar
0ead1fd87e
minor update
2012-03-05 09:42:52 +00:00
Miroslav Stampar
ac5a752b12
Oracle's XMLType doesn't like '#' char too
2012-03-01 11:59:37 +00:00
Miroslav Stampar
761ec7529a
minor appereance fix
2012-03-01 11:52:30 +00:00
Miroslav Stampar
f4e410db16
minor fix
2012-03-01 10:17:39 +00:00
Miroslav Stampar
1ec56f93ec
minor update
2012-03-01 10:10:19 +00:00
Miroslav Stampar
2d3c12d2d0
shorter single line info
2012-03-01 09:10:24 +00:00
Miroslav Stampar
37db27b720
turning back on automatic adjusting of delays in time based queries
2012-02-29 15:51:23 +00:00
Miroslav Stampar
0205d96d7b
minor fix
2012-02-29 15:38:01 +00:00
Miroslav Stampar
1bdc07c279
minor update
2012-02-29 15:02:24 +00:00
Miroslav Stampar
8b9c5c66cc
code refactoring regarding charsetType inside inference/bisection
2012-02-29 14:36:23 +00:00
Miroslav Stampar
f6f98f1b41
minor improvement
2012-02-29 14:19:59 +00:00
Miroslav Stampar
10dd9096f7
one more just in case fix for safeSQLIdentificator naming on MSSQL --tables
2012-02-29 14:05:53 +00:00
Miroslav Stampar
d06182347f
fixing few potential problems
2012-02-29 13:56:40 +00:00
Miroslav Stampar
c39d85420a
removing PGP Key ID from my info too (used only few times in couple of years)
2012-02-29 09:56:41 +00:00
Miroslav Stampar
f142c0f782
minor update
2012-02-28 14:04:13 +00:00
Miroslav Stampar
22b3fa0749
minor update
2012-02-27 15:28:36 +00:00
Miroslav Stampar
a9bf0297f6
moving injection data to HashDB
2012-02-27 13:44:07 +00:00
Miroslav Stampar
68e08d2749
minor fix for not displaying 'None' but None in enumeration when data unavailable
2012-02-27 13:15:10 +00:00
Miroslav Stampar
a424de3102
minor fix
2012-02-27 12:55:28 +00:00
Miroslav Stampar
1e82405bb9
HashDB is now supported in -d too
2012-02-27 12:14:01 +00:00
Miroslav Stampar
3909658fc2
few minor just in case updates
2012-02-27 11:15:53 +00:00
Miroslav Stampar
85125018a1
minor bug fix
2012-02-25 22:54:32 +00:00
Miroslav Stampar
5d307cf886
minor update
2012-02-25 10:54:39 +00:00
Miroslav Stampar
06ab3fa134
minor update
2012-02-25 10:53:38 +00:00
Miroslav Stampar
74b19a0386
minor update
2012-02-25 10:43:10 +00:00
Miroslav Stampar
5b67af3b20
minor update
2012-02-24 15:03:39 +00:00
Miroslav Stampar
8a203ef79d
making session data strictly dependent on url through HashDB helper functions
2012-02-24 14:58:24 +00:00
Miroslav Stampar
c36cbbb3ae
minor fix
2012-02-24 14:54:10 +00:00
Miroslav Stampar
26b33154ab
optimal fix related to the last commit
2012-02-24 14:28:41 +00:00
Miroslav Stampar
9d6fd2e507
bug fix for --schema --technique=BST
2012-02-24 14:12:19 +00:00
Miroslav Stampar
f94b91ad87
added helper function for HashDB data storing/retrieval
2012-02-24 13:07:20 +00:00
Miroslav Stampar
b481c0352f
minor update
2012-02-24 11:25:56 +00:00
Miroslav Stampar
1f6ce265b9
minor fix
2012-02-24 11:05:04 +00:00
Miroslav Stampar
5afbd52b61
more update related to last commits
2012-02-24 10:57:23 +00:00
Miroslav Stampar
570d3a19c2
more general fix
2012-02-24 10:53:28 +00:00
Miroslav Stampar
e8352e504f
fixing problems with chars deletition by logging messages in inference mode
2012-02-24 10:48:19 +00:00
Miroslav Stampar
71028a81f5
fix for proper retrieval of columns in SQLite
2012-02-24 09:55:13 +00:00
Miroslav Stampar
f9d2971474
minor just in case fix
2012-02-23 16:37:06 +00:00
Miroslav Stampar
7941504c3a
minor update
2012-02-23 15:32:36 +00:00
Miroslav Stampar
0478e4166a
minor justin case fix
2012-02-23 15:19:20 +00:00
Miroslav Stampar
086c3a3662
minor fix
2012-02-23 13:31:50 +00:00
Bernardo Damele
82e2f27024
Minor doc update
2012-02-23 10:45:52 +00:00
Miroslav Stampar
da22e82309
minor fix
2012-02-23 10:29:55 +00:00
Miroslav Stampar
2866aaf4cf
minor fixes
2012-02-23 10:16:58 +00:00
Miroslav Stampar
4e44900039
minor update
2012-02-23 10:01:45 +00:00
Miroslav Stampar
03070d17a6
minor update
2012-02-23 09:40:03 +00:00
Miroslav Stampar
a0106ff7b4
minor update of CHANGES
2012-02-23 09:34:18 +00:00
Miroslav Stampar
6e54cb171f
minor code restyling
2012-02-22 15:53:36 +00:00
Miroslav Stampar
61a25418a9
minor update
2012-02-22 10:45:10 +00:00
Miroslav Stampar
b3bd4144f5
removing of unused imports together with some general code refactoring
2012-02-22 10:40:11 +00:00
Miroslav Stampar
386e98a0e3
using UNION SELECT for where=..NEGATIVE
2012-02-22 09:41:58 +00:00
Miroslav Stampar
c9d570c83b
minor update
2012-02-21 13:49:30 +00:00
Miroslav Stampar
686eacda9a
minor update regarding --hex
2012-02-21 13:38:18 +00:00
Miroslav Stampar
bcf3255fe1
implementation of switch --hex for 4 major DBMSes
2012-02-21 11:44:48 +00:00
Miroslav Stampar
77723a7aee
minor update
2012-02-21 10:24:04 +00:00
Miroslav Stampar
d70f4b7150
adding hex conversion functions to queries.xml for 4 major DBMSes
2012-02-21 10:10:43 +00:00
Miroslav Stampar
3e4db6d140
minor fix for Python v2.6
2012-02-20 19:35:57 +00:00
Bernardo Damele
f55ad46119
Use %TEMP% environment variable as temporary directory (--tmp-path overwrites this btw) folder with direct connection (-d). Via SQL injection, env variables do not work apparently
2012-02-20 11:06:55 +00:00
Miroslav Stampar
08bf8c201f
few minor fixes
2012-02-20 10:24:55 +00:00
Miroslav Stampar
bc4dd7c0dd
fix for -g
2012-02-20 10:02:19 +00:00
Bernardo Damele
121148f27f
There was no point relying on a support table (sqlmapoutput) to get the stdout of executed OS commands when using direct connection (-d) and it saves also number of requests.
...
Also, BULK INSERT apparently does not work on MSSQL when running as Network Service (at least on Windows XP) so one more reason to avoid using support table.
Minor fix also to threat MSSQL's EXEC statements as SELECT ones
2012-02-17 15:54:49 +00:00
Bernardo Damele
ebd40b3933
Minor bug fix to make --file-read and --os-bof syntactically work also with -d (direct connection)
2012-02-17 15:16:05 +00:00
Miroslav Stampar
aee269cc14
gazillion changes, nothing will work, muhahaha
2012-02-17 14:22:48 +00:00
Miroslav Stampar
dcf7277a0f
some more refactorings
2012-02-16 14:42:28 +00:00
Miroslav Stampar
6632aa7308
some more refactoring
2012-02-16 13:46:01 +00:00
Miroslav Stampar
32ca99da53
minor update of FAQ files
2012-02-16 13:26:00 +00:00
Miroslav Stampar
17d9cc0c7a
replaced tabs with spaces and removed some pesky unprintable chars
2012-02-16 13:15:01 +00:00
Miroslav Stampar
844fc8addb
minor cleanup
2012-02-16 10:19:36 +00:00
Miroslav Stampar
0e23521adc
some more refactoring
2012-02-16 09:54:29 +00:00
Miroslav Stampar
e1f86c97c4
minor refactoring
2012-02-16 09:46:41 +00:00
Miroslav Stampar
bcf9fc6c6f
minor refactoring
2012-02-16 09:32:47 +00:00
Miroslav Stampar
8d7912ad34
minor update and refactoring
2012-02-15 14:05:50 +00:00
Miroslav Stampar
bf923a97df
minor update
2012-02-15 13:45:10 +00:00
Miroslav Stampar
122db6e164
minor update
2012-02-15 13:24:02 +00:00
Miroslav Stampar
9059d30312
adding first code example for SPL snippets
2012-02-15 13:17:01 +00:00
Miroslav Stampar
edeb4b6113
bug fix for --os-shell on Windows (echo ... > requires double quotes if the piped filename contains whitespace, otherwise doesn't hurt)
2012-02-15 11:14:01 +00:00
Miroslav Stampar
35fa214a1e
minor update (it was working before too, but this is cleaner)
2012-02-15 10:14:29 +00:00
Bernardo Damele
1c44d6d3c7
Fixed annoying bug that prevented proper checkBooleanExpression() function to work with direct connection (-d). Now DBMS fingerprint should work properly with -d
2012-02-14 17:29:00 +00:00
Miroslav Stampar
23cc8b6974
minor fix for special cases when parameter value contains html encoded characters
2012-02-14 14:08:10 +00:00
Miroslav Stampar
c1ab02494c
minor grammar and cosmetics
2012-02-14 13:18:37 +00:00
Miroslav Stampar
bb5113980b
minor update
2012-02-14 10:27:56 +00:00
Miroslav Stampar
3f15c52188
minor change in workflow for "tainted" parameter values
2012-02-14 09:26:52 +00:00
Miroslav Stampar
2604e73d88
minor change in workflow
2012-02-13 11:18:47 +00:00
Miroslav Stampar
96f589fc89
minor fix
2012-02-12 19:22:33 +00:00
Miroslav Stampar
8a2bd3897d
minor output fix
2012-02-12 19:11:54 +00:00
Miroslav Stampar
48583a9b8d
update of THANKS file
2012-02-12 19:01:36 +00:00
Miroslav Stampar
c1368053e5
minor fix
2012-02-12 18:46:25 +00:00
Miroslav Stampar
249cb48b0b
minor fix
2012-02-10 15:59:11 +00:00
Miroslav Stampar
6be95194a7
matter of concision
2012-02-10 15:37:43 +00:00
Miroslav Stampar
eab7a54e03
cosmetics
2012-02-10 15:34:04 +00:00
Miroslav Stampar
92590d0d59
minor fix
2012-02-10 15:26:55 +00:00
Miroslav Stampar
e36e9de57e
minor update by request
2012-02-10 15:12:23 +00:00
Miroslav Stampar
b140ef4a14
minor update (preparing for switching to HashDB from old sessionFile)
2012-02-10 10:24:48 +00:00
Miroslav Stampar
7bca926a0b
fixes, updates, patches
2012-02-09 10:16:58 +00:00
Miroslav Stampar
948cf25de4
more consistent
2012-02-09 09:53:40 +00:00
Miroslav Stampar
980367b7b2
minor update
2012-02-09 09:48:47 +00:00
Miroslav Stampar
7e9e582eca
minor update
2012-02-08 14:23:57 +00:00
Miroslav Stampar
1d4b10dbd1
bug fix
2012-02-08 13:55:50 +00:00
Miroslav Stampar
2662fe84f7
minor update
2012-02-08 12:02:50 +00:00
Miroslav Stampar
85a4ef6593
minor update
2012-02-08 12:00:03 +00:00
Miroslav Stampar
93d7d6c355
minor patch
2012-02-08 10:38:58 +00:00
Miroslav Stampar
6bedb80ffa
adding --force-ssl switch (most useful in combination with -r)
2012-02-08 09:11:57 +00:00
Miroslav Stampar
11887f331d
update of THANKS file
2012-02-07 15:00:01 +00:00
Miroslav Stampar
e50d64546f
minor fix
2012-02-07 14:57:48 +00:00
Miroslav Stampar
2b05ded9c3
just a makeup
2012-02-07 12:05:23 +00:00
Miroslav Stampar
b4f4a982e4
minor update
2012-02-07 11:37:54 +00:00
Miroslav Stampar
11af0b1bbc
minor fix
2012-02-07 11:16:03 +00:00
Miroslav Stampar
f7bf1fbe94
upgrade/fixes for direct DBMS access
2012-02-07 10:46:55 +00:00
Miroslav Stampar
af71e3c563
minor update
2012-02-06 09:48:44 +00:00
Miroslav Stampar
e94f86a1ad
minor update
2012-02-03 15:46:28 +00:00
Miroslav Stampar
22f4d5650f
fix for retrieving version of backend OS on MSSQL
2012-02-03 15:42:36 +00:00
Miroslav Stampar
a48fc4efec
minor update
2012-02-03 15:32:23 +00:00
Miroslav Stampar
e3466fa5d8
minor update
2012-02-03 15:28:11 +00:00
Miroslav Stampar
2136b3447d
better solution
2012-02-03 15:22:21 +00:00
Miroslav Stampar
f86c365694
added one more failsafe for MSSQL --tables
2012-02-03 10:56:39 +00:00
Miroslav Stampar
8c45ff0d57
bug fix
2012-02-03 10:38:04 +00:00
Bernardo Damele
c0f4b4632d
Minor fix
2012-02-02 12:55:39 +00:00
Miroslav Stampar
a7970d094a
minor update
2012-02-01 15:10:06 +00:00
Miroslav Stampar
e56309f3b1
minor makeup update
2012-02-01 15:04:56 +00:00
Miroslav Stampar
8405ef59ac
some estetic updates
2012-02-01 14:49:42 +00:00
Miroslav Stampar
f4e7bf1d51
minor update regarding support for Unicode characters in Oracle
2012-02-01 14:17:27 +00:00
Miroslav Stampar
704488a4e4
proper retrieval of unicode characters in inference mode on MSSQL
2012-02-01 13:01:46 +00:00
Miroslav Stampar
a6c2fc7ecc
some refactoring on MSSQL support
2012-02-01 12:53:07 +00:00
Miroslav Stampar
df43157284
minor patch
2012-02-01 12:28:06 +00:00
Miroslav Stampar
2ee198a381
minor "patch"
2012-02-01 11:00:01 +00:00
Miroslav Stampar
2589521ecf
fix of a wrong assumption (e.g. decodeIntToUnicode(12345) has been returning a "09" instead of a single unicode character)
2012-02-01 10:38:43 +00:00
Miroslav Stampar
4d9dcbf5db
minor fix
2012-02-01 10:14:23 +00:00
Miroslav Stampar
f79d01183d
minor update
2012-02-01 09:23:52 +00:00
Miroslav Stampar
2face9799a
minor fix
2012-02-01 09:17:38 +00:00
Miroslav Stampar
7d37a650d0
minor fix
2012-01-30 14:41:17 +00:00
Miroslav Stampar
91ebadff75
minor update
2012-01-30 13:32:52 +00:00
Miroslav Stampar
d8c343a88a
minor update
2012-01-30 13:29:43 +00:00
Miroslav Stampar
f8ae0e5272
minor update
2012-01-30 13:20:33 +00:00
Miroslav Stampar
46f42f2fe4
minor fix
2012-01-30 13:10:35 +00:00
Miroslav Stampar
f2857e38ba
minor update
2012-01-30 10:19:03 +00:00
Miroslav Stampar
594579bef4
fix for a bug regarding --cookie and --crawl
2012-01-30 09:17:22 +00:00
Miroslav Stampar
2094c715db
minor update
2012-01-23 09:44:17 +00:00
Miroslav Stampar
9e5cf70a5a
minor fix
2012-01-20 11:13:25 +00:00
Miroslav Stampar
de94bee7b5
minor fix
2012-01-20 00:11:19 +00:00
Miroslav Stampar
9eee6c252d
minor update for --scope
2012-01-16 10:28:21 +00:00
Miroslav Stampar
527ce070a3
minor fix
2012-01-16 10:04:18 +00:00
Miroslav Stampar
b2dad63000
some more refactoring
2012-01-13 22:00:34 +00:00
Miroslav Stampar
8e4b8d345f
refactoring
2012-01-13 21:55:39 +00:00
Bernardo Damele
ec9cc19951
Minor bug fixes for -d
2012-01-13 21:46:21 +00:00
Miroslav Stampar
e5fe029a78
minor beautification
2012-01-13 21:03:50 +00:00
Miroslav Stampar
6634c4ac20
minor update
2012-01-13 21:01:58 +00:00
Miroslav Stampar
23117e72ca
minor improvement
2012-01-13 20:56:06 +00:00
Bernardo Damele
5e853cae64
Minor bug fix so now when the back-end DBMS operating system is Windows 2000, it sets the temporary folder automatically to C:\WINNT\Temp - the user does not need to provide it anymore with --tmp-path C:\\WINNT\\Temp
2012-01-13 18:08:44 +00:00
Bernardo Damele
0043336620
Minor fix and removed leftover debug message
2012-01-13 17:04:59 +00:00
Bernardo Damele
e59ace5409
minor bug fix
2012-01-13 16:57:45 +00:00
Bernardo Damele
b03f91437b
Minor code refactoring
2012-01-13 16:49:52 +00:00
Miroslav Stampar
337973df77
reverting last 2 commits (better solution was the original one)
2012-01-13 15:58:47 +00:00
Miroslav Stampar
1f53ff0633
minor update regarding last commit
2012-01-13 15:56:50 +00:00
Miroslav Stampar
ff96c537a9
minor update for multithreaded mode
2012-01-13 15:50:38 +00:00
Miroslav Stampar
accac776fe
some fixes
2012-01-13 14:10:53 +00:00
Bernardo Damele
7e560eec1f
Minor fix
2012-01-13 12:54:45 +00:00
Miroslav Stampar
dd295bbd4a
minor update regarding -d and time based injections
2012-01-13 12:45:02 +00:00
Miroslav Stampar
04686b83e3
minor update
2012-01-13 11:16:26 +00:00
Miroslav Stampar
305371b7a9
minor update
2012-01-12 14:58:23 +00:00
Miroslav Stampar
a0e4d27bad
replacing leftovers of sqlmap.sourceforge.net with www.sqlmap.org
2012-01-11 15:32:30 +00:00
Miroslav Stampar
95f89ab63a
updating copyright date
2012-01-11 14:59:46 +00:00
Miroslav Stampar
1d0b43b1a2
implemented mechanism for merging cookies by request
2012-01-11 14:28:08 +00:00
Miroslav Stampar
f1147035cf
minor concision/beautification update
2012-01-10 11:50:26 +00:00
Miroslav Stampar
fecdce5801
implemented --tables over information_schema for MSSQL as a failover option for BOOLEAN technique too
2012-01-09 21:09:05 +00:00
Miroslav Stampar
ff52931140
some refactoring (skipping duplicate messages in case that UNION/ERROR techniques failed and BOOLEAN/TIMED/STACKED are not available)
2012-01-07 19:30:35 +00:00
Miroslav Stampar
18930539cd
more concise language
2012-01-07 17:45:45 +00:00
Miroslav Stampar
138b8039b3
better language
2012-01-07 17:35:53 +00:00
Miroslav Stampar
2b5e429dc2
one more level of defense against user himself
2012-01-07 17:16:14 +00:00
Miroslav Stampar
a675c88894
minor check added for invalid urls (e.g. deliberately too long)
2012-01-07 16:06:18 +00:00
Miroslav Stampar
164c8a4020
better message in case of update error
2012-01-07 15:47:38 +00:00
Miroslav Stampar
5a8fc44119
minor update
2012-01-07 15:26:54 +00:00
Miroslav Stampar
3f4afdf251
minor fix (crashing if no : in value)
2012-01-07 14:54:56 +00:00
Miroslav Stampar
f85c5b3f4d
minor update
2012-01-06 00:23:49 +00:00
Miroslav Stampar
759465bde5
minor fix
2012-01-06 00:06:38 +00:00
Miroslav Stampar
40398f358c
minor update
2012-01-05 14:55:23 +00:00
Miroslav Stampar
1f085a0241
now [SLEEPTIME] is changeable properly in vivo
2012-01-05 14:45:05 +00:00
Miroslav Stampar
9d50c806e1
bug fix
2012-01-05 10:55:58 +00:00
Miroslav Stampar
5053c2f685
update of doc/THANKS
2012-01-05 10:28:54 +00:00
Miroslav Stampar
804629832d
minor fix
2012-01-05 10:24:27 +00:00
Miroslav Stampar
ff090b0111
update of THANKS file
2012-01-03 23:47:30 +00:00
Miroslav Stampar
ea87c89c25
minor fix
2012-01-03 23:44:56 +00:00
Miroslav Stampar
f412706fee
minor update for MSSQL --tables (fallback to other method)
2012-01-03 18:01:14 +00:00
Miroslav Stampar
13f2afbbc9
minor fix
2012-01-03 17:28:50 +00:00
Miroslav Stampar
6f5ef23f28
minor update/patch
2012-01-01 22:55:32 +00:00
Miroslav Stampar
300abc2ba2
minor update regarding unicode unescaping
2012-01-01 22:31:09 +00:00
Miroslav Stampar
40991a5d52
minor fix
2011-12-31 01:03:54 +00:00
Miroslav Stampar
94d43a4135
minor bug fix
2011-12-30 14:20:06 +00:00
Miroslav Stampar
63bc4ce116
minor patch
2011-12-30 14:11:02 +00:00
Miroslav Stampar
29f502fe29
some refactoring
2011-12-28 16:27:17 +00:00
Miroslav Stampar
37d78ffe01
minor optimization
2011-12-28 15:59:30 +00:00
Miroslav Stampar
6c49af090c
minor language patch
2011-12-28 14:18:17 +00:00
Miroslav Stampar
8750532c3d
minor fix
2011-12-28 14:13:36 +00:00
Miroslav Stampar
22c3fe49bb
some refactoring
2011-12-28 13:50:03 +00:00
Miroslav Stampar
dda979a15a
minor refactoring
2011-12-27 12:31:29 +00:00
Miroslav Stampar
0a6334db22
minor speedup
2011-12-27 11:41:57 +00:00
Miroslav Stampar
b02363b1aa
minor update
2011-12-27 11:25:40 +00:00
Miroslav Stampar
b604057e54
minor update
2011-12-26 16:09:46 +00:00
Miroslav Stampar
068ff92dc4
optimizing a bit pyDes module used in Oracle hash cracking
2011-12-26 15:33:49 +00:00
Miroslav Stampar
08071f42d0
minor update
2011-12-26 14:31:59 +00:00
Miroslav Stampar
366e86c560
minor "patch"
2011-12-26 14:08:25 +00:00
Miroslav Stampar
c20546dcaa
minor refactoring
2011-12-26 12:24:39 +00:00
Miroslav Stampar
b71a81041d
implemented --tor-port by request
2011-12-23 10:57:09 +00:00
Miroslav Stampar
89d2c7c042
minor update
2011-12-22 20:54:20 +00:00
Miroslav Stampar
abb401879c
minor update
2011-12-22 20:42:57 +00:00
Miroslav Stampar
087e29d272
minor update
2011-12-22 20:14:56 +00:00
Miroslav Stampar
8a7b0406c8
minor optimization
2011-12-22 20:08:28 +00:00
Miroslav Stampar
094129a656
minor optimization
2011-12-22 15:42:21 +00:00
Miroslav Stampar
8585107e3d
minor update
2011-12-22 12:21:30 +00:00
Miroslav Stampar
f622995a29
compatibility with partial union and error technique resumed data
2011-12-22 12:20:21 +00:00
Miroslav Stampar
58a4a02b7e
minor fix
2011-12-22 11:56:42 +00:00
Miroslav Stampar
6f8d8a15aa
minor update
2011-12-22 11:55:02 +00:00
Miroslav Stampar
9f68e54fff
minor cleanup
2011-12-22 10:59:28 +00:00
Miroslav Stampar
aaa29d1f24
minor fix
2011-12-22 10:51:41 +00:00
Miroslav Stampar
4a1a0773b7
speedup of UNION dumping
2011-12-22 10:44:14 +00:00
Miroslav Stampar
1ae413a206
some refactoring/speedup around UNION technique
2011-12-22 10:32:21 +00:00
Miroslav Stampar
b77e2042f2
some optimization
2011-12-21 23:23:00 +00:00
Miroslav Stampar
a6310c0b21
minor update
2011-12-21 23:04:36 +00:00
Miroslav Stampar
526aacb640
code cleanup
2011-12-21 22:59:23 +00:00
Miroslav Stampar
41ccf88990
some more refactoring
2011-12-21 22:09:21 +00:00
Miroslav Stampar
0a039d84e0
some more refactoring
2011-12-21 19:40:42 +00:00
Miroslav Stampar
d9d4e3ea9b
minor fix
2011-12-21 17:43:50 +00:00
Miroslav Stampar
41b60b26fc
minor refactoring
2011-12-21 14:25:39 +00:00
Miroslav Stampar
81bd9a201b
minor refactoring
2011-12-21 11:50:49 +00:00
Miroslav Stampar
0b54553a76
quick fix for AV engines
2011-12-21 10:22:03 +00:00
Miroslav Stampar
113ebf5e9d
minor update
2011-12-20 16:08:17 +00:00
Miroslav Stampar
8bfff4a28e
minor update
2011-12-20 15:01:27 +00:00
Miroslav Stampar
d3a428c9c8
minor bug fix regarding dumping tables with safe quotes
2011-12-20 13:17:24 +00:00
Miroslav Stampar
d1bfdc6a48
minor fix for --start/--stop mechanism in pivot dumping mode
2011-12-20 13:04:57 +00:00
Miroslav Stampar
95cd9e2af3
adding support for scanning Host header values (-p host)
2011-12-20 12:52:41 +00:00
Miroslav Stampar
bdc724cb46
minor bug fix
2011-12-20 10:34:28 +00:00
Miroslav Stampar
1b16b5e0f1
minor fix
2011-12-20 09:10:44 +00:00
Miroslav Stampar
dcf842692b
minor fix
2011-12-16 12:34:26 +00:00
Miroslav Stampar
641055144a
minor beautification
2011-12-16 11:49:20 +00:00
Miroslav Stampar
ebc04a3d5f
minor fix
2011-12-16 11:44:33 +00:00
Miroslav Stampar
7d2fce16dc
minor fix
2011-12-16 11:40:23 +00:00
Miroslav Stampar
cff21814bb
minor patch for MSSQL 2008
2011-12-16 11:23:41 +00:00
Miroslav Stampar
c57941c102
minor beautification
2011-12-15 23:33:44 +00:00
Miroslav Stampar
27d244b326
minor update
2011-12-15 23:29:11 +00:00
Miroslav Stampar
563c0c1066
adding switch --tor-type
2011-12-15 23:19:55 +00:00
Miroslav Stampar
316e27a809
minor update
2011-12-15 10:19:31 +00:00
Miroslav Stampar
c98f5f6f94
minor fix
2011-12-15 09:28:58 +00:00
Miroslav Stampar
4150fadb05
minor update of THANKS file
2011-12-14 14:58:51 +00:00
Miroslav Stampar
12d7c4fe3c
minor fix
2011-12-14 14:57:35 +00:00
Miroslav Stampar
8793fbc9f5
minor update
2011-12-14 12:59:25 +00:00
Miroslav Stampar
1fd1ec22a1
minor fix
2011-12-14 12:03:21 +00:00
Miroslav Stampar
e6820ebbd2
minor update
2011-12-14 10:26:03 +00:00
Miroslav Stampar
364113441b
adding (for now) hidden switch --tor-http (utilizing Tor proxy bundles)
2011-12-14 10:19:45 +00:00
Miroslav Stampar
73a500833d
minor bug fix
2011-12-12 14:38:06 +00:00
Miroslav Stampar
25cde9e2c7
minor fixes
2011-12-12 09:45:40 +00:00
Bernardo Damele
8fe72d87a8
minor bug fix for mysql -d --file-read
2011-12-06 10:57:23 +00:00
Miroslav Stampar
0f5d48ff20
minor update
2011-12-05 09:25:56 +00:00
Miroslav Stampar
408d12dc41
minor fix
2011-12-05 08:26:00 +00:00
Miroslav Stampar
a8a5e61ee1
minor update
2011-12-05 00:06:32 +00:00
Miroslav Stampar
3fb22ef80a
another minor update
2011-12-05 00:03:05 +00:00
Miroslav Stampar
a462a9df43
minor update
2011-12-04 23:59:10 +00:00
Miroslav Stampar
b99c157d0f
patching DNS-leakage of SocksiPy extra module
2011-12-04 23:58:22 +00:00
Miroslav Stampar
9bc735963b
update of redirection mechanism (now 3-state - redirected, original and "ignored" (containing redirection message itself))
2011-12-04 22:42:19 +00:00
Miroslav Stampar
ec895c3d1a
revert of last commit
2011-12-04 16:37:18 +00:00
Miroslav Stampar
393843bf87
it seems that SOCKS4 is safer solution for TOR socks access
2011-12-04 16:23:08 +00:00
Miroslav Stampar
2adf358524
minor update
2011-12-03 13:17:43 +00:00
Miroslav Stampar
5f7dbec41f
minor patch
2011-12-03 12:11:46 +00:00
Miroslav Stampar
39b406c5c1
fix for --search on Oracle
2011-12-02 18:13:27 +00:00
Miroslav Stampar
b9ae28dd5e
minor beautification
2011-12-02 14:11:43 +00:00
Miroslav Stampar
96aacbf945
upgrade of --search mechanism (lowest common denominator is now searched for - e.g. if -D -T and -C are given then -C is searched for in -D and -T)
2011-12-02 13:32:30 +00:00
Miroslav Stampar
b03a5e8928
people don't know what's "standard deviation" and they are wrongly connecting it's value in seconds to the --time-sec value
2011-12-01 13:30:47 +00:00
Miroslav Stampar
94790bf08a
minor update (removing reference to Microsoft Access for Generic payload)
2011-12-01 13:25:27 +00:00
Miroslav Stampar
32ab7171ea
minor update
2011-12-01 10:07:39 +00:00
Miroslav Stampar
9975ff8d17
minor update
2011-11-30 19:26:03 +00:00
Miroslav Stampar
f1dfa5c860
minor update
2011-11-30 17:44:34 +00:00
Miroslav Stampar
71c46f50aa
adding option --csv-del
2011-11-30 17:39:41 +00:00
Miroslav Stampar
02bd9a54f3
minor update
2011-11-30 17:19:21 +00:00
Miroslav Stampar
872a73f631
minor refactoring
2011-11-29 19:17:07 +00:00
Miroslav Stampar
3cd8f47686
minor bug fix
2011-11-29 17:17:06 +00:00
Miroslav Stampar
2842c13d75
minor update
2011-11-29 16:59:06 +00:00
Miroslav Stampar
6806cbd6e9
minor language update
2011-11-28 16:01:01 +00:00
Miroslav Stampar
d958c2fe48
minor fix
2011-11-28 11:21:39 +00:00
Miroslav Stampar
df4e3be191
using MySQL comments in explicit MySQL payloads where not comments stated in title (as we already use in MySQL UNION payloads; in lots of cases minus character is either filtered or "exploded" - seen in lots of WP vulnerabilites; also, it was a false claim by myself previously that # is no longer a valid MySQL comment syntax in never versions)
2011-11-23 22:57:02 +00:00
Miroslav Stampar
885b432808
minor update
2011-11-23 21:39:53 +00:00
Miroslav Stampar
ba4234dc42
switching from HTTP proxy to SOCKS proxy for --tor (sick and tired of Polipo/Privoxy bull; either Tor flag is overwritten every here and there or they are putting all kinds of filter warnings)
2011-11-23 21:17:08 +00:00
Miroslav Stampar
8ea9b19b66
minor update regarding dumping of table content in --forms mode
2011-11-23 20:56:22 +00:00
Miroslav Stampar
d6f936b98d
minor update
2011-11-23 15:51:48 +00:00
Miroslav Stampar
40f21c3917
minor update
2011-11-23 15:38:31 +00:00
Miroslav Stampar
14e8ca6d41
minor fix
2011-11-23 14:26:40 +00:00
Miroslav Stampar
9b99530add
minor bug fix
2011-11-23 08:14:20 +00:00
Miroslav Stampar
d5cddd40f6
minor fix
2011-11-23 03:03:31 +00:00
Miroslav Stampar
6bfb7c2137
minor fix
2011-11-23 00:04:14 +00:00
Miroslav Stampar
d8047c79f3
reverting back last two commits
2011-11-22 15:28:31 +00:00
Miroslav Stampar
73276c0785
even better (added long before plugins table)
2011-11-22 15:23:31 +00:00
Miroslav Stampar
ff07031170
better choice than character_sets (lesser rows in start and avoiding one rare problem - description column name based)
2011-11-22 15:20:12 +00:00
Miroslav Stampar
f39170a2c4
minor update
2011-11-22 15:06:51 +00:00
Miroslav Stampar
e33f70269b
minor optimization
2011-11-22 12:44:28 +00:00
Miroslav Stampar
501fd85fa1
minor optimization
2011-11-22 12:40:12 +00:00
Miroslav Stampar
2e10de8921
minor update
2011-11-22 12:18:24 +00:00
Miroslav Stampar
ac041399f0
minor patch
2011-11-22 11:04:43 +00:00
Miroslav Stampar
9697e80013
some more optimizations
2011-11-22 10:54:29 +00:00
Miroslav Stampar
267d67b024
minor update
2011-11-22 10:41:56 +00:00
Miroslav Stampar
b117c40aa5
major improvement of HashDB speed in multi-threaded mode
2011-11-22 10:09:35 +00:00
Miroslav Stampar
e94efff187
some more optimization
2011-11-22 09:00:00 +00:00
Miroslav Stampar
2ed3efba12
speed optimization and bug fix (kb.absFilePaths were not stored previously; also, they are now extracted only in heuristic phase)
2011-11-22 08:39:13 +00:00
Miroslav Stampar
493e436e16
minor update
2011-11-22 07:32:39 +00:00
Miroslav Stampar
e905ea2a54
minor bug fix
2011-11-22 07:07:52 +00:00
Miroslav Stampar
f1f0828b28
minor update
2011-11-21 22:27:47 +00:00
Miroslav Stampar
704e1a4e74
minor minor update
2011-11-21 22:19:52 +00:00
Miroslav Stampar
fcac3d494b
minor beautification
2011-11-21 22:18:04 +00:00
Miroslav Stampar
753dcb3450
minor update
2011-11-21 22:12:24 +00:00
Miroslav Stampar
da51e8a9d1
minor fix
2011-11-21 21:55:05 +00:00
Miroslav Stampar
eee03871d7
minor refactoring
2011-11-21 21:31:08 +00:00
Miroslav Stampar
4fa24ec704
minor improvement
2011-11-21 17:39:18 +00:00
Miroslav Stampar
65b2b0ad87
adding switch --eval
2011-11-21 16:41:02 +00:00
Miroslav Stampar
0ce885e6e6
adding base64encode tampering script
2011-11-21 12:47:23 +00:00
Miroslav Stampar
df0b451389
minor update
2011-11-20 23:17:57 +00:00
Miroslav Stampar
49fddaf668
minor update (for cases with 404 original page - e.g. time based injections in some cases)
2011-11-20 23:11:18 +00:00
Miroslav Stampar
8c32b3653b
minor update of false positive check (in considerable amount of cases minus char is filtered/used for other means)
2011-11-20 20:27:30 +00:00
Miroslav Stampar
440b7efe55
minor optimization
2011-11-20 20:14:47 +00:00
Miroslav Stampar
7c1af97852
minor optimization
2011-11-20 19:38:56 +00:00
Miroslav Stampar
e1a92d59de
implementing WordPress phpass hash cracking routine
2011-11-20 19:10:46 +00:00
Miroslav Stampar
f1979936c8
minor update
2011-11-18 15:32:33 +00:00
Miroslav Stampar
2ff555bf10
minor fix for --profile switch
2011-11-16 16:41:22 +00:00
Miroslav Stampar
0df768e24a
minor refactoring/optimization
2011-11-16 16:06:21 +00:00
Miroslav Stampar
7314de3490
language update
2011-11-15 11:17:39 +00:00
Miroslav Stampar
ad2762118d
minor update
2011-11-14 15:10:39 +00:00
Miroslav Stampar
b888829d12
minor update
2011-11-14 11:39:18 +00:00
Miroslav Stampar
367627c331
minor fix for Python 2.6
2011-11-13 19:09:13 +00:00
Miroslav Stampar
76fb6ba666
minor update
2011-11-13 10:38:27 +00:00
Miroslav Stampar
bbb7e1562d
adding AGAINST full-text search boundaries
2011-11-12 14:16:43 +00:00
Miroslav Stampar
ccbd93cc2e
fix for redirect/HOST header bug
2011-11-11 11:28:27 +00:00
Miroslav Stampar
1061c06617
improvement of redirecting code
2011-11-11 11:07:49 +00:00
Miroslav Stampar
e183437f0b
minor typo
2011-11-10 10:30:53 +00:00
Miroslav Stampar
62f8f8d36c
bug fix (thanks to zhen zhou)
2011-11-10 10:22:35 +00:00
Miroslav Stampar
81ca6f00f0
removed by request
2011-11-09 12:49:28 +00:00
Miroslav Stampar
088be1b364
minor fix
2011-11-07 09:02:21 +00:00
Miroslav Stampar
fda27470da
minor update
2011-11-07 08:43:53 +00:00
Miroslav Stampar
6c07573e30
minor update
2011-11-06 11:42:02 +00:00
Miroslav Stampar
030c57a0c8
minor update
2011-11-06 11:18:16 +00:00
Miroslav Stampar
2ad43411ba
update
2011-11-06 08:58:20 +00:00
Miroslav Stampar
2dbd51e357
fix for google searches
2011-11-06 08:55:09 +00:00
Miroslav Stampar
5f08b90b6c
commiting new tampering scripts contributed by Roberto Salgado
2011-11-03 16:04:34 +00:00
Miroslav Stampar
61e3621855
minor update
2011-11-02 14:33:23 +00:00
Miroslav Stampar
24bda96d9e
adding items from John the Ripper's word list to the dictionary for Oracle cracking
2011-11-02 11:21:49 +00:00
Miroslav Stampar
6ec522e14b
removal of minor obsolete thingy
2011-11-02 10:41:12 +00:00
Miroslav Stampar
ea125d820d
some more speed ups for hash cracking
2011-11-02 09:57:42 +00:00
Miroslav Stampar
2f355db230
minor fix
2011-11-02 09:32:15 +00:00
Miroslav Stampar
0e96af65e6
minor update
2011-11-02 07:06:07 +00:00
Miroslav Stampar
d735582536
major speed improvement of hash cracking
2011-11-02 06:53:43 +00:00
Miroslav Stampar
b3a57391e4
minor update
2011-11-01 20:39:22 +00:00
Miroslav Stampar
3e3f037f1e
improvement of hash cracking routine
2011-11-01 19:58:22 +00:00
Miroslav Stampar
4cafc5f31b
language update
2011-11-01 19:09:17 +00:00
Miroslav Stampar
43340a7ea5
language
2011-11-01 19:06:27 +00:00
Miroslav Stampar
f9bb762d1d
minor improvement (resuming of already cracked values)
2011-11-01 19:00:34 +00:00
Miroslav Stampar
c0cd29f01c
minor update
2011-10-31 15:20:40 +00:00
Miroslav Stampar
60cadf4747
better regex used
2011-10-29 10:31:52 +00:00
Miroslav Stampar
ef987c6954
adding compatibility support for using --crawl and --forms together
2011-10-29 09:32:20 +00:00
Miroslav Stampar
ddc4dfe5ff
minor refactoring for regarding --forms
2011-10-29 08:32:24 +00:00
Miroslav Stampar
d7866ac78d
added support for automatic filtering of badly formed HTML in --forms mode
2011-10-28 21:28:03 +00:00
Miroslav Stampar
1b45c5b56a
bug fix
2011-10-28 15:24:35 +00:00
Miroslav Stampar
f574760c12
minor update
2011-10-28 13:16:22 +00:00
Miroslav Stampar
bd7da45546
minor update
2011-10-28 13:07:23 +00:00
Miroslav Stampar
f7be0ca4e2
minor fix
2011-10-28 12:49:35 +00:00
Miroslav Stampar
6c0e8b0ea8
returning alphabetically sorted database and table names
2011-10-28 12:40:59 +00:00
Miroslav Stampar
666a7da12a
minor update
2011-10-28 11:28:21 +00:00
Miroslav Stampar
b83fe6113e
turning off time adjustment off (now is shown as a tip) because it seems that it never was actually used (payload always left the same)
2011-10-28 11:25:07 +00:00
Miroslav Stampar
e290f2b80b
minor update
2011-10-28 11:11:55 +00:00
Miroslav Stampar
2e5222bfd8
adding INSERT/UPDATE generic boundaries
2011-10-28 11:00:09 +00:00
Miroslav Stampar
7ce3af68fc
fixing support for parsing BURP logs
2011-10-27 17:31:34 +00:00
Miroslav Stampar
6b7920d89a
minor patch for --tor
2011-10-27 10:52:06 +00:00
Miroslav Stampar
3c31ccd16e
minor update
2011-10-26 22:37:04 +00:00
Miroslav Stampar
9d31230d5e
minor update
2011-10-26 21:56:26 +00:00
Miroslav Stampar
d64c0af461
minor update
2011-10-26 14:31:00 +00:00
Miroslav Stampar
9c1d1ca5d8
minor update
2011-10-26 14:13:38 +00:00
Miroslav Stampar
2a72c1ae68
minor fix
2011-10-26 11:30:10 +00:00
Miroslav Stampar
a99547363f
some fixes
2011-10-26 11:24:15 +00:00
Miroslav Stampar
3d883a2218
minor update
2011-10-26 11:10:15 +00:00
Miroslav Stampar
d467b40ff6
minor fix
2011-10-26 10:54:43 +00:00
Miroslav Stampar
8d668b1833
some updates regarding hash attack
2011-10-26 10:30:32 +00:00
Miroslav Stampar
f41ae9cf49
minor update
2011-10-26 09:40:47 +00:00
Miroslav Stampar
0b68144c8f
minor fixes for hash cracking
2011-10-26 09:29:41 +00:00
Miroslav Stampar
18affca0bc
minor update
2011-10-26 09:14:18 +00:00
Miroslav Stampar
64ca01ea0e
minor update
2011-10-25 22:06:47 +00:00
Miroslav Stampar
35c889a411
minor update
2011-10-25 18:07:33 +00:00
Miroslav Stampar
ee76fed56a
minor update
2011-10-25 17:48:20 +00:00
Miroslav Stampar
41ad7f9eab
minor update
2011-10-25 17:44:30 +00:00
Miroslav Stampar
86b4a3562f
added switch --check-tor
2011-10-25 17:37:43 +00:00
Miroslav Stampar
24d495368e
minor update
2011-10-25 14:03:11 +00:00
Miroslav Stampar
38e2d0896b
new tamper script
2011-10-25 13:40:32 +00:00
Miroslav Stampar
9523da7663
minor optimization
2011-10-25 13:21:01 +00:00
Miroslav Stampar
eaaf6041b9
minor fix
2011-10-25 11:20:42 +00:00
Miroslav Stampar
c1486ed4be
adding usage of non-encoded/decoded post data (if data is recognized to be already encoded) by user request
2011-10-25 09:53:44 +00:00
Miroslav Stampar
b07f165d60
quick fix
2011-10-24 18:11:34 +00:00
Miroslav Stampar
23bf52e496
minor refactoring
2011-10-24 09:55:50 +00:00
Miroslav Stampar
cd00c0d084
minor patch
2011-10-24 09:43:59 +00:00
Miroslav Stampar
6d64f87190
minor update
2011-10-24 00:46:54 +00:00
Miroslav Stampar
20ae1c2187
added switch --logic-negative
2011-10-24 00:40:06 +00:00
Miroslav Stampar
8bd3cfdc8e
minor update
2011-10-24 00:17:38 +00:00
Miroslav Stampar
d39d36f7a7
minor language beautification
2011-10-23 23:27:56 +00:00
Miroslav Stampar
7c626f1dbe
minor fix
2011-10-23 23:18:39 +00:00
Miroslav Stampar
d77a5f5928
update (generalizing ORDER BY approach)
2011-10-23 23:02:01 +00:00
Miroslav Stampar
1dd3fae930
minor fix
2011-10-23 22:27:45 +00:00
Miroslav Stampar
0c29311eb2
minor update
2011-10-23 22:24:57 +00:00
Miroslav Stampar
5863429fc1
minor update
2011-10-23 21:17:45 +00:00
Miroslav Stampar
4a469c3258
minor update
2011-10-23 21:12:34 +00:00
Miroslav Stampar
1f7d87c6a4
bug fix for --code (previously redirecting codes where not considered)
2011-10-23 20:48:37 +00:00
Miroslav Stampar
77e630d89e
replaced longer CHAR form of escaped MySQL strings with more compact hex form
2011-10-23 20:19:42 +00:00
Miroslav Stampar
3f0517d3f3
support for non-latin (e.g. cyrillic) URLs
2011-10-23 17:02:48 +00:00
Miroslav Stampar
1c3f4e9e54
minor update
2011-10-23 08:44:21 +00:00
Miroslav Stampar
25f0ec3597
some minor range to xrange conversion (where safe to do)
2011-10-21 22:34:27 +00:00
Miroslav Stampar
eb240243ea
minor update
2011-10-21 22:21:41 +00:00
Miroslav Stampar
b4ce857f9b
added some comments
2011-10-21 21:29:24 +00:00
Miroslav Stampar
7a3096ce25
some refactoring
2011-10-21 21:12:48 +00:00
Miroslav Stampar
9356f8005c
important bug fix
2011-10-21 21:07:06 +00:00
Miroslav Stampar
0a8e45955c
minor update
2011-10-21 20:44:18 +00:00
Miroslav Stampar
566d6e4974
minor fix
2011-10-21 20:21:29 +00:00
Miroslav Stampar
05b9951a8b
minor beautification
2011-10-21 09:19:31 +00:00
Miroslav Stampar
0db0571f35
minor patch
2011-10-21 09:06:00 +00:00
Miroslav Stampar
12a7fd4054
quick fix
2011-10-20 08:28:57 +00:00
Miroslav Stampar
1cec29925c
added new tampering script by request
2011-10-19 22:07:23 +00:00
Miroslav Stampar
0cbcbf159c
minor fix
2011-10-19 21:35:01 +00:00
Miroslav Stampar
b6ccc0cc43
minor update
2011-10-18 14:35:42 +00:00
Miroslav Stampar
597d554153
minor update
2011-10-18 13:05:49 +00:00
Miroslav Stampar
7f9f744b87
update regarding last commit
2011-10-12 12:37:05 +00:00
Miroslav Stampar
39e33bea99
important fix (LIMIT m,n should not be considered deterministic in column by column table dumping)
2011-10-12 12:31:47 +00:00
Miroslav Stampar
e3a719e7d2
minor update
2011-10-11 22:40:00 +00:00
Miroslav Stampar
7956390631
minor update
2011-10-11 22:27:49 +00:00
Miroslav Stampar
a7a29f33ad
minor update
2011-10-11 21:58:57 +00:00
Miroslav Stampar
dacfeafc5f
minor optimization
2011-10-10 17:45:16 +00:00
Miroslav Stampar
4989e8e6d3
minor update
2011-10-10 17:29:54 +00:00
Miroslav Stampar
c204f2b221
minor optimization
2011-10-10 14:47:48 +00:00
Miroslav Stampar
47b27a5988
minor improvement of HashDB
2011-10-10 14:23:17 +00:00
Miroslav Stampar
323aa7bf2f
minor update
2011-10-09 21:21:41 +00:00
Miroslav Stampar
a31a0aa8d4
minor update
2011-10-06 22:29:49 +00:00
Miroslav Stampar
8720aad6dc
transformed cDel to pDel as a more generic option
2011-10-06 22:03:33 +00:00
Miroslav Stampar
dd0ed5f5da
adding redirect response to the traffic file
2011-09-28 08:13:46 +00:00
Miroslav Stampar
6d2536f217
minor update
2011-09-27 22:27:34 +00:00
Miroslav Stampar
c0910ca2c8
added one more warning message by request
2011-09-27 22:25:15 +00:00
Miroslav Stampar
b888a84764
minor update
2011-09-27 14:31:58 +00:00
Miroslav Stampar
88f1110c44
adding a new (for now) hidden switch --test-filter for filtering tests by their name
2011-09-27 14:09:25 +00:00
Miroslav Stampar
fd9acfd7d2
fix
2011-09-26 13:36:08 +00:00
Miroslav Stampar
b3b4459c72
minor fix
2011-09-26 13:01:43 +00:00
Miroslav Stampar
34738129c9
minor update
2011-09-25 21:27:58 +00:00
Miroslav Stampar
7e80274fac
refactoring
2011-09-25 21:10:45 +00:00
Miroslav Stampar
744636a8c1
switching to SQLite resume support (on error and union techniques this moment)
2011-09-25 20:36:32 +00:00
Miroslav Stampar
2d7d84e16b
minor fix
2011-09-25 19:42:24 +00:00
Miroslav Stampar
ba5eff1de6
minor bug fix
2011-09-23 18:29:45 +00:00
Miroslav Stampar
0c9944daa8
update for THANKS file
2011-09-20 22:18:20 +00:00
Miroslav Stampar
af94ac7f02
minor fix
2011-09-20 22:16:56 +00:00
Miroslav Stampar
d95ff4350d
bug fix
2011-09-20 13:08:35 +00:00
Miroslav Stampar
4a3580d10b
minor fix
2011-09-19 19:08:08 +00:00
Miroslav Stampar
af7af0a1df
added version check (no more crashes on Python > 3 and < 2.6
2011-09-12 22:48:57 +00:00
Bernardo Damele
f890b29f81
Proper reference to Metasploit Framework as now it's version 4, not 3 anymore
2011-09-12 17:26:22 +00:00
Miroslav Stampar
4fb6dab1a2
minor bug fix
2011-09-12 14:15:57 +00:00
Miroslav Stampar
9a1ac96756
bug fix
2011-09-11 17:22:27 +00:00
Miroslav Stampar
1bdde51d0e
minor just in case update
2011-09-11 16:41:07 +00:00
Miroslav Stampar
02f993583b
minor bug fix
2011-09-09 11:36:09 +00:00
Miroslav Stampar
2f4e34f5a0
minor improvement for URI injections
2011-09-08 11:13:12 +00:00
Miroslav Stampar
d434047482
minor bug fix
2011-09-05 09:28:40 +00:00
Miroslav Stampar
382db1b67a
degrading Microsoft Access UNION tests for one level down (it really does take toooooo long to scan a site with no vulnerable parameters and normal level)
2011-08-31 20:35:57 +00:00
Miroslav Stampar
793f1d7774
new tampering script
2011-08-29 15:42:01 +00:00
Miroslav Stampar
08e0eb9b61
minor lower/upper case fix
2011-08-29 13:47:32 +00:00
Miroslav Stampar
9be89422da
implemented parameter --skip
2011-08-29 13:29:42 +00:00
Miroslav Stampar
e0f521cf9d
minor update regarding --randomize
2011-08-29 13:08:25 +00:00
Miroslav Stampar
ac00014c4a
implemented --randomize switch by request
2011-08-29 12:50:52 +00:00
Miroslav Stampar
d283e3eb3c
adding support for pre-WHERE injections
2011-08-24 09:04:18 +00:00
Miroslav Stampar
8fe069b495
minor fix
2011-08-23 21:48:39 +00:00
Miroslav Stampar
01014eca17
by request
2011-08-23 21:45:01 +00:00
Miroslav Stampar
606debe55c
better language
2011-08-23 21:42:34 +00:00
Miroslav Stampar
699cb89711
minor corrections to the definition and minor typos
2011-08-23 16:56:13 +00:00
Miroslav Stampar
cfc1f2b70b
minor update
2011-08-22 22:43:14 +00:00
Miroslav Stampar
f4127a80d7
improvement of UNION based injection detection (with non-NULL kb.uChar values searching of the content inside -1 UNION.. pages is used)
2011-08-22 21:43:46 +00:00
Miroslav Stampar
dafc4d93bd
typo
2011-08-22 15:05:54 +00:00
Miroslav Stampar
8a174248dc
fix for a bug reported by blueBoy
2011-08-20 20:08:11 +00:00
Miroslav Stampar
fb6a84b10b
minor update (when columns are missing from information_schema too)
2011-08-18 07:03:53 +00:00
Miroslav Stampar
cb32d46f2a
minor minor update
2011-08-18 06:09:12 +00:00
Miroslav Stampar
54bcc35ba7
important bug fix (connection exception was causing losing of already retrieved data)
2011-08-17 22:31:33 +00:00
Miroslav Stampar
9d31322f3d
update regarding special case when conf.uChar appears only in testable pages
2011-08-17 21:40:42 +00:00
Miroslav Stampar
75ec146224
minor beautification
2011-08-17 21:17:02 +00:00
Miroslav Stampar
f46baac70b
bug fix (when comment is None this was errornous)
2011-08-17 10:58:29 +00:00
Bernardo Damele
9361e633f4
Minor bug fix - some applications do really set cookies like param="value" with double-quotes
2011-08-16 09:21:01 +00:00
Miroslav Stampar
e1dbb4443b
minor update related to the last commit
2011-08-16 07:01:14 +00:00
Miroslav Stampar
7cc5743c5d
minor adjustment of a time based char retrievals (no more infinite increasing of timeSec value for problematic characters)
2011-08-16 06:50:20 +00:00
Miroslav Stampar
600ef3eace
minor patch
2011-08-16 06:22:04 +00:00
Miroslav Stampar
262996fc5b
bug fix
2011-08-16 06:14:40 +00:00
Miroslav Stampar
df4abf1af1
lowering constant value from 10 to 7 for da peace in da houz
2011-08-12 17:19:19 +00:00
Bernardo Damele
702ed73a65
Added --code switch to match in boolean-based tests against the HTTP response code
2011-08-12 16:48:11 +00:00
Bernardo Damele
e34787db99
update
2011-08-12 16:06:41 +00:00
Bernardo Damele
fff4c34e33
Search for --string and --regexp matches also in HTTP response headers
2011-08-12 15:33:37 +00:00
Bernardo Damele
6d22d09a61
doc updated
2011-08-12 15:03:39 +00:00
Bernardo Damele
5e5133b8e7
Should be fixed now
2011-08-12 15:00:11 +00:00
Bernardo Damele
1505cb2a80
typo
2011-08-12 14:51:39 +00:00
Bernardo Damele
702ca22d54
Minor bug fix for URI injections
2011-08-12 14:48:44 +00:00
Bernardo Damele
28bba9f5e6
More verbose warning message
2011-08-12 13:47:38 +00:00
Miroslav Stampar
10bdd90e60
minor speed optimizations (as a result of profiling)
2011-08-12 13:40:37 +00:00
Bernardo Damele
36280b33fa
Ask the user wheather or not to adjust the time delay - there have been a case where the forcing of conf.timeSec screwed the result in an extremely lagged and unreliable site
2011-08-12 13:06:40 +00:00
Bernardo Damele
997c9ba1e8
Minor adjustments to user's manual
2011-08-12 12:56:55 +00:00
Miroslav Stampar
41ae9bc7ff
minor bug fix
2011-08-09 14:20:25 +00:00
Miroslav Stampar
2ad267132a
minor update for empty normal responses (like AJAX requests)
2011-08-05 10:55:21 +00:00
Miroslav Stampar
e849b71027
minor typo
2011-08-03 14:31:42 +00:00
Miroslav Stampar
538b49bcc5
removing word "dramatically". i was too excited at the moment :). it is cool and all but we shouldn't put "highly subjective" attribs in reports
2011-08-03 13:26:38 +00:00
Miroslav Stampar
f7562da754
from now on proper union column count should be displayed in injection info output
2011-08-03 10:34:50 +00:00
Miroslav Stampar
13eb20cea1
minor beautification
2011-08-03 10:12:06 +00:00
Bernardo Damele
2e20eb1a88
Minor fix
2011-08-03 10:08:59 +00:00
Miroslav Stampar
a3a649ed03
minor update
2011-08-03 09:11:50 +00:00
Miroslav Stampar
9423d15fb3
ORDER BY technique used for finding proper UNION col count (dramatical improvement of speed and capabilities) and one minor bug fix
2011-08-03 09:08:16 +00:00
Miroslav Stampar
07afcd5440
fix for a bug reported by Ahmed Shawky (when user uses --suffix intermixing test default comments with the provided suffix is a big no no)
2011-08-02 18:20:21 +00:00
Miroslav Stampar
07c3d4fb18
minor adjustment
2011-08-02 17:35:43 +00:00
Miroslav Stampar
edab7d01a5
minor fix
2011-08-02 17:31:13 +00:00
Bernardo Damele
c15439ab7f
Minor improvement to --passwords output
2011-08-02 09:04:34 +00:00
Miroslav Stampar
cb0981d858
proper way of handling 0 length results (as in __goInferenceProxy)
2011-08-02 08:39:32 +00:00
Miroslav Stampar
0643ced651
minor update
2011-08-02 08:12:43 +00:00
Miroslav Stampar
457f501bbd
proper fix
2011-08-01 23:48:38 +00:00
Bernardo Damele
ad4584da70
Minor bug fix when dumping tables with UNION query technique on Access, Firebird and MaxDB
2011-08-01 23:44:14 +00:00
Miroslav Stampar
4ca81dd345
quick fix
2011-08-01 23:25:58 +00:00
Bernardo Damele
cbd0ea0866
Possible fix for a minor bug
2011-08-01 23:24:39 +00:00
Miroslav Stampar
b9438c3e14
doc/THANKS update
2011-08-01 10:18:00 +00:00
Miroslav Stampar
e0fda9f985
minor fix
2011-08-01 10:13:25 +00:00
Miroslav Stampar
79b4e26e23
bug fix
2011-08-01 00:17:26 +00:00
Miroslav Stampar
018d7ed646
improvement for limited queries (more stable to have TOP/LIMIT/OFFSET mechanisms as part of a subquery)
2011-07-31 23:40:09 +00:00
Miroslav Stampar
0627bb02cb
minor beautification
2011-07-31 10:21:47 +00:00
Miroslav Stampar
93ae1dfa2b
minor bug fix
2011-07-31 08:52:48 +00:00
Miroslav Stampar
1f06d7d7de
update of THANKS file
2011-07-30 21:51:37 +00:00
Miroslav Stampar
4d923ec375
change in invalid logic regarding --sql-shell (retrieving output for non-query commands did nothing at all)
2011-07-30 21:46:59 +00:00
Miroslav Stampar
a6ade08c28
just in case commit to prevent join string iteration over 'None' values
2011-07-30 13:01:37 +00:00
Miroslav Stampar
68ae8ea5b2
minor refactoring
2011-07-29 10:54:25 +00:00
Miroslav Stampar
e522263640
fix for a neverending data retrieval in large full inband cases
2011-07-29 10:45:09 +00:00
Miroslav Stampar
4ce93221d1
minor update
2011-07-28 09:24:37 +00:00
Miroslav Stampar
684ddc43e6
minor patch
2011-07-28 08:53:09 +00:00
Miroslav Stampar
3fc603843e
minor fix
2011-07-27 23:26:36 +00:00
Miroslav Stampar
107089c00b
bug fix
2011-07-27 08:25:51 +00:00
Miroslav Stampar
f7eaffcec5
i believe that this could be ok
2011-07-26 21:28:48 +00:00
Bernardo Damele
37de709df2
leftover
2011-07-26 11:20:07 +00:00
Bernardo Damele
a2483b3bc4
Aligned OS takeover functionalities to recent Metasploit improvements
2011-07-26 10:29:14 +00:00
Bernardo Damele
ea00c94648
Minor bug fix
2011-07-26 10:10:05 +00:00
Bernardo Damele
938716e361
Proper fix for --start and --stop consistency amongst different techniques
2011-07-26 10:06:28 +00:00
Bernardo Damele
e71f96afe7
Reverted dumb "fix"
2011-07-26 09:42:09 +00:00
Miroslav Stampar
6bbb8139a0
update (smaller memory footprint in postprocessing phase because of safecharencode part)
2011-07-25 20:40:31 +00:00
Miroslav Stampar
5770c08784
minor optimization and refactoring
2011-07-25 20:17:44 +00:00
Bernardo Damele
0a7a648694
Minor bug fix for --start, now all techniques return the same result (before blind techniques returned from one entry behind)
2011-07-25 11:15:18 +00:00
Bernardo Damele
6cbb927012
Partial fix for -o not resumed at following runs if missing from command line
2011-07-25 11:05:49 +00:00
Bernardo Damele
50f4c4af52
Minor bug fix to parse also MSSQL 2008 R2 signatures
2011-07-24 23:43:01 +00:00
Bernardo Damele
b8e2d60bfa
Added MSSQL 2008 R2 signatures
2011-07-24 23:42:32 +00:00
Bernardo Damele
48f580fb10
Minor adjustments to MSSQL fingerprint
2011-07-24 23:30:23 +00:00
Bernardo Damele
4550fa9e40
update
2011-07-24 22:43:22 +00:00
Bernardo Damele
99a0b62d0d
Minor adjustments
2011-07-24 22:26:11 +00:00
Miroslav Stampar
ca83305b58
added MySQL updatexml error-based payload
2011-07-24 21:08:32 +00:00
Miroslav Stampar
2033a28ae7
minor update regarding last commit (cleaner code)
2011-07-24 20:44:17 +00:00
Miroslav Stampar
3a3561fdaa
doing proper big table support for partial union too
2011-07-24 20:36:44 +00:00
Miroslav Stampar
ec1bc0219c
hello big tables, this is sqlmap, sqlmap this is big tables
2011-07-24 09:19:33 +00:00
Miroslav Stampar
82e1e61554
minor speedup
2011-07-23 19:51:19 +00:00
Miroslav Stampar
094dc91e2d
minor update (prior to some changes regarding large content retrieval)
2011-07-23 19:04:59 +00:00
Miroslav Stampar
a89140e1ce
revisit of Oracle error-based payloads (added replace for '@' as a problematic char for XMLType function)
2011-07-23 06:07:00 +00:00
Miroslav Stampar
8a00ca83af
refactoring. nothing special changed
2011-07-21 10:18:11 +00:00
Miroslav Stampar
963f54e6d2
minor fix for parameters containing '=' inside values itself (remark: no parameter name will have '=' nor '%3d' inside; tested and it does a good job)
2011-07-21 10:06:52 +00:00
Miroslav Stampar
7881ded60d
quick fix (this other library was doing problems)
2011-07-20 22:20:16 +00:00
Bernardo Damele
d6b52242c7
Meterpreter's sniffer extension freezes 64-bit systems
...
Meterpreter's priv extension is loaded by default since Metasploit 3.5 or so.
There is no shellcodeexec 64-bit yet, anyway as the Metasploit payload is encoded with a 32-bit encoded (alphanumeric), it's all fine.
2011-07-20 13:50:02 +00:00
Bernardo Damele
5a1c9a42a3
Minor bug fix
2011-07-20 13:45:34 +00:00
Bernardo Damele
29b5115906
Minor bug fix
2011-07-20 13:28:10 +00:00
Miroslav Stampar
9d996c07fb
another quick fix
2011-07-20 13:00:34 +00:00
Miroslav Stampar
fad77dd078
fix for a ImportError bug reported by g@brindi.si
2011-07-20 12:18:36 +00:00
Miroslav Stampar
9cf33ec997
now status is no longer represented in percentage (impossible in cases where we need to support too small and too large dictionaries - technical issues regarding counting) but by the rotating char
2011-07-15 13:24:13 +00:00
Miroslav Stampar
ff8fc90ac7
bug fix
2011-07-13 06:44:15 +00:00
Miroslav Stampar
9c694ce3ec
bug fix (--tables --columns)
2011-07-12 23:27:47 +00:00
Miroslav Stampar
5c162efbd8
more optimization
2011-07-12 23:21:15 +00:00
Miroslav Stampar
9933edc718
optimization of reflective removal mechanism
2011-07-12 22:28:19 +00:00
Miroslav Stampar
4cb9988243
quick fix
2011-07-12 21:09:33 +00:00
Bernardo Damele
cda25cda2f
Cosmetics
2011-07-12 20:49:27 +00:00
Miroslav Stampar
3583d6dd1b
quick fixes, more work to do
2011-07-12 20:32:19 +00:00
Miroslav Stampar
0126b8eb0e
minor revert (it's illegal to use append for updating one array with another array)
2011-07-12 19:34:54 +00:00
Bernardo Damele
48b7245a33
Minor bug fix
2011-07-12 15:47:04 +00:00
Bernardo Damele
0b8c6e4c81
Minor bug fix
2011-07-12 15:30:40 +00:00
Bernardo Damele
eeb4436471
renamed
2011-07-12 12:48:15 +00:00
Bernardo Damele
42c5bab013
renamed
2011-07-11 23:37:10 +00:00
Miroslav Stampar
a46b5230f5
minor "patch"
2011-07-11 20:33:16 +00:00
Miroslav Stampar
1f826684f6
disabling multiprocessing (maybe permanently) support for Windows as of complications with sharing dictionary iterator
2011-07-11 13:16:59 +00:00
Miroslav Stampar
7bc6280d53
possible fix for a multi-processing "problem" reported by christopher.oakley@gmail.com
2011-07-11 11:40:27 +00:00
Bernardo Damele
4ae71fd5f4
Updated docstring
2011-07-11 10:39:30 +00:00
Bernardo Damele
86d28947aa
updated
2011-07-11 10:07:36 +00:00
Bernardo Damele
2b6b80d7f8
Updated docstring
2011-07-11 10:04:19 +00:00
Bernardo Damele
c9e6fc7695
Added new tamper script, tamper/space2mssqlblank.py from RS
2011-07-11 09:49:58 +00:00
Bernardo Damele
e47f873fa4
Renamed space2extrarandomblank.py to space2mysqlblank.py
2011-07-11 09:49:03 +00:00
Bernardo Damele
c9ba58acb6
Moved MS Access UNION query tests after generic as generic test must identify MSSQL
2011-07-11 09:47:52 +00:00
Bernardo Damele
1e1f429668
Minor minor fix
2011-07-11 09:22:47 +00:00
Miroslav Stampar
5014475637
minor update (changing form of payload[i+1] with payload[i+1:i+2] which is much safer for not crashing the script with invalid char index)
2011-07-11 09:22:29 +00:00
Miroslav Stampar
7a6bddf811
minor fixes pointed by RS
2011-07-11 09:08:24 +00:00
Miroslav Stampar
f5e45bf113
quick fix for a bug reported by jovon.itwaru@gmail.com
2011-07-11 08:54:39 +00:00
Miroslav Stampar
98958f8808
minor minor update
2011-07-10 15:41:45 +00:00
Miroslav Stampar
0d6afca7db
adding new switch '--smart' by request
2011-07-10 15:16:58 +00:00
Miroslav Stampar
5d31eb5ef7
cosmetics and also tested against testing env - works perfectly
2011-07-10 09:07:07 +00:00
Miroslav Stampar
b3acaf85d8
minor update
2011-07-10 08:58:55 +00:00
Miroslav Stampar
eb42cedf2a
adding extractvalue MySQL >= 5.1 error payload ( http://www.notsosecure.com/folder2/2010/06/29/mysql-exploitation-with-error-messages/ ) - untested (lack of particular ver for testing) and prone to level/risk adjustment
2011-07-10 08:54:22 +00:00
Miroslav Stampar
b7433011f8
new tamper script by request
2011-07-08 22:48:03 +00:00
Miroslav Stampar
1e182e6c72
quick fix
2011-07-08 22:34:44 +00:00
Bernardo Damele
05cb65b106
Added one more tamper script from Roberto Salgado and minor adjustment to others
2011-07-08 13:43:34 +00:00
Bernardo Damele
3985a81cb9
Update email addresses
2011-07-08 13:39:47 +00:00
Bernardo Damele
651349e229
More verbose critical message
2011-07-08 13:12:53 +00:00
Bernardo Damele
062c156fc0
Added another tamper script from Roberto Salgado
2011-07-08 11:03:14 +00:00
Miroslav Stampar
93219b9e13
i've accidentally left table_schema removed while doing some tests. now it should be ok
2011-07-08 10:24:46 +00:00
Bernardo Damele
b5dd4d4a63
Minor bug fix for Microsoft Access case expressions (like --common-tables) in UNION query SQL injection
2011-07-08 10:19:01 +00:00
Miroslav Stampar
02bfd05b20
more general approach
2011-07-08 10:03:14 +00:00
Miroslav Stampar
5443e06430
cosmetics (in debug mode [0] is used)
2011-07-08 09:43:52 +00:00
Miroslav Stampar
c463c411b9
minor update
2011-07-08 09:32:58 +00:00
Miroslav Stampar
ba2c06c9dc
quick fix
2011-07-08 09:01:32 +00:00
Miroslav Stampar
c517e97a44
few fixes and minor cosmetics
2011-07-08 06:02:31 +00:00
Bernardo Damele
aedcf8c8d7
Changed homepage address
2011-07-07 20:10:03 +00:00
Bernardo Damele
736327c893
Added two tamper scripts contributed by Roberto Salgado
2011-07-07 18:45:07 +00:00
Bernardo Damele
067354b97f
Revert of last commit and proper fix to detect UNION query SQL injection against Microsoft Access
2011-07-07 13:20:40 +00:00
Bernardo Damele
c6a0b84242
Some more common tables and columns
2011-07-07 00:23:54 +00:00
Bernardo Damele
9e1a6beb7a
Major bug fix in UNION detection, it was a leftover
2011-07-07 00:06:20 +00:00
Bernardo Damele
fcd4e94c04
Higher chances to detect UNION query SQL injection against Microsoft Access
2011-07-06 23:52:44 +00:00
Bernardo Damele
9d2aadd4a6
missing docstring details
2011-07-06 22:53:22 +00:00
Bernardo Damele
23b4efdcaf
Revamp of tamper scripts, now supporting dependencies() function as well. Improved a lot the docstring and retested all. Added a new one from Ahmad too.
2011-07-06 21:04:45 +00:00
Bernardo Damele
0d28c1e9e7
cosmetics
2011-07-06 20:41:13 +00:00
Bernardo Damele
6f6038b534
Quick fix (revert..)
2011-07-06 11:32:12 +00:00
Miroslav Stampar
93b296e02c
few bug fixes (NTLM credential parsing was wrong), some switch reordering (few Misc to General), implemented --check-waf switch (irony is that this will also be called highly experimental/unstable while other things will be called "major/turbo/super bug fix/implementation")
2011-07-06 05:44:47 +00:00
Miroslav Stampar
b8ffcf9495
few fixes here and there and multi-core processing for dictionary based hash attack
2011-07-04 19:58:41 +00:00
Bernardo Damele
da049110df
Minor revert
2011-07-04 15:23:05 +00:00
Miroslav Stampar
a1fe9d07ca
minor revert
2011-07-02 23:00:22 +00:00
Miroslav Stampar
34d9a91af1
bulk of fixes
2011-07-02 22:48:56 +00:00
Bernardo Damele
861cdb1b14
cosmetics
2011-07-01 10:04:34 +00:00
Miroslav Stampar
4513ef409e
massive (like really massive) dictionary support
2011-06-30 23:44:49 +00:00
Miroslav Stampar
43db6b03a7
update with a feature request (file with list of wordlist files)
2011-06-30 08:42:43 +00:00
Miroslav Stampar
366c2d279d
minor update
2011-06-30 08:02:52 +00:00
Miroslav Stampar
d063ae91eb
propset update
2011-06-30 07:55:07 +00:00
Miroslav Stampar
b361f60644
minor changes
2011-06-30 07:52:13 +00:00
Miroslav Stampar
f3013e4a29
minor update
2011-06-30 06:39:32 +00:00
Miroslav Stampar
caf22b58bc
new tamper script
2011-06-30 06:34:24 +00:00
Miroslav Stampar
8a36f7fc03
fix for a bug reported by aboynes@gmail.com (UnboundLocalError: local variable 'infoMsg' referenced before assignment)
2011-06-29 18:04:58 +00:00
Miroslav Stampar
9e453e8709
fix for a bug reported by nightman@email.de
2011-06-29 17:49:59 +00:00
Miroslav Stampar
be9b8bca78
bug fix
2011-06-29 17:39:58 +00:00
Bernardo Damele
6d606d417b
Preparing for PostgreSQL 9.0 DLL (--os-pwn) compilation on Windows 64-bit
2011-06-28 13:41:15 +00:00
Bernardo Damele
ddb6ba6d47
Added PostgreSQL 9.0 shared object for Linux 32-bit
2011-06-28 13:14:32 +00:00
Bernardo Damele
1698630bc0
Added PostgreSQL 9.0 shared object for Linux 64-bit
2011-06-28 13:12:18 +00:00
Bernardo Damele
d3b44a5f58
Added copyright
2011-06-28 10:59:20 +00:00
Bernardo Damele
fe686feefa
Added support for direct connection (-d switch) to IBM DB2
2011-06-28 10:52:07 +00:00
Bernardo Damele
9eb683531d
Minor improvement at blind SQL inj technique for DB2
2011-06-27 22:28:12 +00:00
Miroslav Stampar
75524c283d
minor update
2011-06-27 21:59:31 +00:00
Miroslav Stampar
4be55c811f
minor update
2011-06-27 21:48:26 +00:00
Miroslav Stampar
831f083223
minor update
2011-06-27 21:38:12 +00:00
Miroslav Stampar
5b4eaf48d9
minor fix (for those blank suffixes out of nowhere at the end of payload - not related to "-- ")
2011-06-27 21:34:49 +00:00
Miroslav Stampar
8a8b94883b
minor update (that default quit in --batch was bothering me - my original idea and it was bad :)
2011-06-27 14:14:49 +00:00
Bernardo Damele
ed4cfbb6d2
Minor fix
2011-06-27 08:58:59 +00:00
Miroslav Stampar
d72db1bf91
minor update (all misc options are alphabetically ordered)
2011-06-27 08:21:33 +00:00
Miroslav Stampar
bedf16b88b
adding payloads for time-based injection on SAP MaxDB (heavy query)
2011-06-26 23:46:09 +00:00
Miroslav Stampar
d0490cc4e7
adding payloads for time-based injection on DB2 (heavy query)
2011-06-26 16:38:22 +00:00
Bernardo Damele
36c96ef796
Added DB2 support - patch provided by Sebastian Bittig
2011-06-25 09:44:24 +00:00
Miroslav Stampar
e00cf81f7e
minor update
2011-06-24 19:50:13 +00:00
Miroslav Stampar
e9286ddd5b
fix for a bug reported by g@brindi.si (UnicodeDecodeError: 'ascii' codec can't decode byte 0xc2 in position
...
47: ordinal not in range(128))
2011-06-24 19:24:11 +00:00
Miroslav Stampar
f434c3b29e
update of THANKS file
2011-06-24 19:06:08 +00:00
Miroslav Stampar
c4cb367e65
looks nicer (though --tor is implicitly converted into --proxy)
2011-06-24 19:00:53 +00:00
Miroslav Stampar
aa83fe5c66
minor update
2011-06-24 18:19:33 +00:00
Miroslav Stampar
21010f702c
minor beautification
2011-06-24 17:46:54 +00:00
Miroslav Stampar
2de88bd90b
minor update
2011-06-24 17:19:24 +00:00
Miroslav Stampar
96190cf594
minor update
2011-06-24 17:15:15 +00:00
Bernardo Damele
b2e6cf3ed9
Enabled --search -C also for Oracle
2011-06-24 14:34:20 +00:00
Bernardo Damele
f7196007ca
--search on Oracle is now consistent with other plugins
2011-06-24 14:33:30 +00:00
Bernardo Damele
ede73d2279
propset
2011-06-24 14:09:41 +00:00
Bernardo Damele
406f2cda09
Got rid of useless TAB completion in --sql-shell
2011-06-24 13:05:13 +00:00
Bernardo Damele
35ce6dedcf
Got rid of useless imports
2011-06-24 09:59:11 +00:00
Bernardo Damele
a78f5b4eb3
Minor adjustment to avoid function and variables with same name
2011-06-24 09:29:11 +00:00
Bernardo Damele
ddfae39d9e
Minor bug fixes for --search with -C
2011-06-24 09:27:54 +00:00
Miroslav Stampar
eaa2a4202f
changing to: --crawl=CRAWLDEPTH
2011-06-24 05:40:03 +00:00
Miroslav Stampar
3717b8423f
cleanest fix this moment (conf.dbms will for sure deal problems later in any form)
2011-06-22 15:48:44 +00:00
Miroslav Stampar
5190440ea2
minor fix
2011-06-22 15:36:59 +00:00
Miroslav Stampar
97d8729d71
probable fix for a bug reported by m4l1c3 (RuntimeError: maximum recursion depth exceeded)
2011-06-22 15:28:49 +00:00
Miroslav Stampar
52ba3c281e
minor update
2011-06-22 14:59:49 +00:00
Miroslav Stampar
4ca37901da
thread safe logging+stdout (no more overlapping of log messages and raw output)
2011-06-22 14:53:42 +00:00
Miroslav Stampar
84bc8c3a37
update
2011-06-22 14:39:31 +00:00
Miroslav Stampar
938db1b513
replacing xmlobject logic with our own
2011-06-22 14:33:52 +00:00
Miroslav Stampar
7c830c2b1a
removing xmlobject
2011-06-22 14:33:03 +00:00
Bernardo Damele
1cb12ea659
replaced third-party library python-mysql with python pymysql, http://code.google.com/p/pymysql/ (MIT license)
2011-06-22 13:31:07 +00:00
Miroslav Stampar
e76cb19e35
minor patch
2011-06-22 09:11:12 +00:00
Miroslav Stampar
019f4d344a
update of THANKS file
2011-06-21 21:03:50 +00:00
Miroslav Stampar
b16b92fe46
minor update
2011-06-21 20:59:34 +00:00
Miroslav Stampar
2220afbdf5
fix by request
2011-06-21 20:50:16 +00:00
Miroslav Stampar
9e232256f4
reverting that last commit because there is a mess with default dumping (startLimit is set to 0 which is not so friendly with --start and --stop logic)
2011-06-21 18:29:23 +00:00
Miroslav Stampar
3536320fc9
--stop is inclusive ("Last query output entry to retrieve")
2011-06-21 18:08:33 +00:00
Miroslav Stampar
dfc02d8c3c
sorry Bernardo, i hope your mobile is turned off :)))
2011-06-20 22:47:24 +00:00
Miroslav Stampar
2a4a284a29
crawler fix (skip binary files)
2011-06-20 22:41:38 +00:00
Miroslav Stampar
20bb1a685b
really minor update
2011-06-20 21:57:53 +00:00
Miroslav Stampar
812cd2f19b
minor update
2011-06-20 21:47:03 +00:00
Miroslav Stampar
e8ac7414f2
bug fix
2011-06-20 21:36:15 +00:00
Miroslav Stampar
d6062e8fc9
minor fix for crawler and far less message overlaps in future
2011-06-20 21:18:12 +00:00
Miroslav Stampar
8968c708a0
minor update
2011-06-20 14:27:24 +00:00
Miroslav Stampar
17fac6f67f
minor update
2011-06-20 13:53:39 +00:00
Miroslav Stampar
29314f425e
minor fix
2011-06-20 13:42:31 +00:00
Miroslav Stampar
d9015ed800
fix for a bug reported by krasn@deventum.com
2011-06-20 13:25:19 +00:00
Miroslav Stampar
f09340fc89
minor update
2011-06-20 12:40:14 +00:00
Miroslav Stampar
4d1fa5596b
added support for --scope in --crawl mode
2011-06-20 12:37:51 +00:00
Miroslav Stampar
42746cc706
bug fix
2011-06-20 12:18:46 +00:00
Miroslav Stampar
67fab9f2e2
putting this to info messages (user needs to know at this place why is it waiting)
2011-06-20 12:17:19 +00:00
Miroslav Stampar
b1426b5131
bug fix
2011-06-20 12:11:09 +00:00
Miroslav Stampar
cda39ca350
minor update
2011-06-20 11:46:23 +00:00
Miroslav Stampar
07e2c72943
adding Beautifulsoup (BSD) into extras; adding --crawl to options
2011-06-20 11:32:30 +00:00
Miroslav Stampar
8c04aa871a
english typo
2011-06-20 11:00:23 +00:00
Bernardo Damele
d7da71ce8e
politeness
2011-06-20 09:10:04 +00:00
Miroslav Stampar
bdb530da1f
minor update
2011-06-19 10:11:27 +00:00
Miroslav Stampar
d5bc149636
made changes by buawig request (504 is treated as a classical timeout)
2011-06-19 09:57:41 +00:00
Miroslav Stampar
83af83da9e
minor beautification (WordsSet is considered as a bad english)
2011-06-18 15:47:19 +00:00
Bernardo Damele
4b94ef2b7c
A little bit more polite
2011-06-18 13:03:55 +00:00
Bernardo Damele
f8c32cf6b9
Moved folder
2011-06-18 12:34:41 +00:00
Bernardo Damele
28ef61b997
Use getPageTextWordsSet() also in --common-columns
2011-06-18 12:30:26 +00:00
Bernardo Damele
6b2f44de14
Minor layout adjustment
2011-06-18 12:27:12 +00:00
Miroslav Stampar
ca6f9acf30
minor fix for resuming in multi threading mode
2011-06-18 12:23:18 +00:00
Bernardo Damele
cd07139919
Layout adjustments
2011-06-18 11:58:14 +00:00
Miroslav Stampar
31ad0875b4
added by request
2011-06-18 11:34:51 +00:00
Miroslav Stampar
e4be141602
minor fix for --smoke-test
2011-06-18 11:26:17 +00:00
Bernardo Damele
c7e1aeeef2
layout
2011-06-18 11:02:48 +00:00
Miroslav Stampar
905fef0eae
now user can explicitly state number of UNION affected columns via --union-cols (e.g. --union-cols=5)
2011-06-18 10:51:14 +00:00
Miroslav Stampar
7c537f6896
adding Chrome to the user-agents.txt
2011-06-18 10:12:06 +00:00
Miroslav Stampar
0c5d7d4535
removing crawling random agent strings as some sites appear different to them (minor possibility to screw blind engine)
2011-06-18 09:56:21 +00:00
Miroslav Stampar
fde3e4cece
better
2011-06-18 09:52:07 +00:00
Miroslav Stampar
2f129b01c0
"Please consider to provide" is a bad English
2011-06-18 09:46:22 +00:00
Miroslav Stampar
1440c9f2d4
minor update
2011-06-17 22:28:07 +00:00
Miroslav Stampar
87e9842371
better language
2011-06-17 22:13:45 +00:00
Miroslav Stampar
ce3170edef
minor update/better language
2011-06-17 22:11:40 +00:00
Miroslav Stampar
ec6fa384eb
update
2011-06-17 22:04:25 +00:00
Miroslav Stampar
0c9fa5c550
fix
2011-06-17 17:12:47 +00:00
Miroslav Stampar
043f2f92c1
minor update
2011-06-17 17:10:52 +00:00
Miroslav Stampar
c9a6aad5c3
minor fix by request
2011-06-17 16:58:50 +00:00
Miroslav Stampar
a0129dcbcb
this is confusing for normal users (i've just get a mail where dude thinks that he needs to use tamper script because of this :)
2011-06-17 16:52:39 +00:00
Miroslav Stampar
f3ee2c09fb
cleaner fix
2011-06-17 15:32:23 +00:00
Miroslav Stampar
bb987ec98f
fix for DNS leakage
2011-06-17 15:23:58 +00:00
Miroslav Stampar
9498a3f259
little stabilization of multi threading
2011-06-17 12:50:28 +00:00
Miroslav Stampar
2171c64213
update by request
2011-06-16 15:05:04 +00:00
Miroslav Stampar
d27afaed7e
some fixes
2011-06-16 14:27:44 +00:00
Miroslav Stampar
6b1d5a0ab8
minor fix
2011-06-16 14:11:30 +00:00
Miroslav Stampar
530c296519
minor fix
2011-06-16 13:56:17 +00:00
Miroslav Stampar
3a883a82fb
minor update
2011-06-16 13:44:50 +00:00
Miroslav Stampar
0eeb48f8f5
some fixes
2011-06-16 13:41:02 +00:00
Miroslav Stampar
7733e5866a
minor update regarding mnemonics (again)
2011-06-16 12:34:38 +00:00
Miroslav Stampar
286e7ee679
minor beautification
2011-06-16 12:29:17 +00:00
Miroslav Stampar
17e4c6b564
minor update regarding mnemonics
2011-06-16 12:26:50 +00:00
Miroslav Stampar
25b923bbc3
minor fixes and minor updates
2011-06-16 12:12:30 +00:00
Miroslav Stampar
3995891ab4
new file containing default settings
2011-06-16 11:43:07 +00:00
Miroslav Stampar
6f681b45ad
cleaning up a bit for a configuration mess
2011-06-16 11:42:13 +00:00
Bernardo Damele
f515c9c9e0
Dealt with SVN update login traceback. Need to investigate further why it asks for credentials sometimes
2011-06-16 10:11:11 +00:00
Miroslav Stampar
63d98d8ce6
fix for a bug reported by rdsears@mtu.edu (ignored config file items)
2011-06-16 08:08:49 +00:00
Miroslav Stampar
ca8a60dd7a
update of doc/THANKS
2011-06-15 19:04:43 +00:00
Miroslav Stampar
afe0579487
minor fixes for pivot dumping
2011-06-15 19:03:37 +00:00
Miroslav Stampar
4188df0501
fixes for Sybase
2011-06-15 18:49:35 +00:00
Miroslav Stampar
4d51fa8155
minor update planned for a long time (in case of heuristic test was positive warn the user properly at the end if program fails)
2011-06-15 17:37:28 +00:00
Miroslav Stampar
e0ad72031f
minor update
2011-06-15 12:04:30 +00:00
Miroslav Stampar
1d93a03eeb
introducing mnemonics
2011-06-15 11:58:50 +00:00
Miroslav Stampar
d55a242908
minor improvement. messages are now warnings (not errors because lots of them are not causing problems for a normal usage) and most of all it's being checked only if the --dependencies is used (until now this switch has been ignored and turned on by default - always)
2011-06-14 19:38:35 +00:00
Miroslav Stampar
a4328e914b
minor update
2011-06-14 19:29:42 +00:00
Miroslav Stampar
1e17c0d4a1
switching to debug mode for missing dependencies
2011-06-14 08:47:06 +00:00
Miroslav Stampar
60ecf95383
fix for a bug reported by seyi.akin@gmail.com
2011-06-14 08:40:25 +00:00
Bernardo Damele
8978fded03
typo fix
2011-06-13 19:00:27 +00:00
Bernardo Damele
7152a1ed3b
Added --dependences to show which sqlmap dependences are not available
2011-06-13 18:44:02 +00:00
Miroslav Stampar
8485827352
adding already cracked words from http://freerainbowtables.com/en/hashcracking/
2011-06-13 14:39:59 +00:00
Miroslav Stampar
87c58c29ef
little update for wordlist file (pron, singles, porn-unknown, rockyou-75)
2011-06-13 13:30:56 +00:00
Miroslav Stampar
0990f16f7f
minor update for invalid cases like 'iso-8859-1 (western europe)'
2011-06-12 08:36:21 +00:00
Miroslav Stampar
2da56ea507
fix of a language bug
2011-06-11 21:17:30 +00:00
Miroslav Stampar
9331abb96f
minor update
2011-06-11 08:33:36 +00:00
Miroslav Stampar
84978f16c9
fix for a "problem" reported by Kirill Morozov (nt authority\\network service)
2011-06-11 07:54:59 +00:00
Miroslav Stampar
f8dde2c23b
adding --titles switch (killer switch for pages with lots of dynamicity and/or international ones)
2011-06-10 23:18:43 +00:00
Miroslav Stampar
15d72ec566
minor improvement for special cases with --string/--regexp
2011-06-10 23:05:47 +00:00
Miroslav Stampar
8fac4605a9
minor fix for None results
2011-06-10 22:28:15 +00:00
Miroslav Stampar
4b784b03fd
adding new tamper script
2011-06-09 12:14:14 +00:00
Miroslav Stampar
71093b1cad
adding one more user friendly message
2011-06-09 09:58:42 +00:00
Miroslav Stampar
0d0f2863af
adding one more tamper script
2011-06-09 09:38:07 +00:00
Miroslav Stampar
03d6031fe7
update of doc/THANKS file
2011-06-09 09:09:52 +00:00
Miroslav Stampar
083a5535eb
added new tamper script by request
2011-06-09 09:01:54 +00:00
Miroslav Stampar
fae089646b
minor fix
2011-06-09 08:38:17 +00:00
Miroslav Stampar
9202fedf7b
minor fix
2011-06-09 08:14:54 +00:00
Miroslav Stampar
af5fe457bd
revert of the revert (it's a good idea to have it like this because of problems with e.g. --text-only and binary content)
2011-06-09 07:53:31 +00:00
Miroslav Stampar
8ec4bc9d9d
revert of the last commit. have to think about it
2011-06-09 06:32:53 +00:00
Miroslav Stampar
9c093d91f2
minor update
2011-06-09 06:14:35 +00:00
Bernardo Damele
d217cf71b2
Minor bug fix
2011-06-08 23:32:44 +00:00
Bernardo Damele
6aade8e6fc
grammar fix, again
2011-06-08 16:40:22 +00:00
Bernardo Damele
9126c84442
Refactoring (standardized with --search -C ...)
2011-06-08 16:39:41 +00:00
Bernardo Damele
d160888784
Grammar fix
2011-06-08 16:25:18 +00:00
Bernardo Damele
1c6ee1dc36
Rephrase
2011-06-08 16:22:16 +00:00
Bernardo Damele
0d8d6a4ace
Cosmetics
2011-06-08 16:08:20 +00:00
Bernardo Damele
70cac24909
Cosmetics
2011-06-08 15:31:27 +00:00
Bernardo Damele
64bef644c3
This was missing
2011-06-08 15:30:59 +00:00
Miroslav Stampar
d8155dfae9
change by request
2011-06-08 14:44:11 +00:00
Miroslav Stampar
6387d98ab0
quick fix
2011-06-08 14:42:48 +00:00
Bernardo Damele
0d3e8a76d8
Cosmetics and a missing param
2011-06-08 14:40:42 +00:00
Miroslav Stampar
4a9640160e
more concise
2011-06-08 14:35:23 +00:00
Miroslav Stampar
6b81eef65a
refactoring
2011-06-08 14:30:12 +00:00
Bernardo Damele
cd6ceb733e
Adjustment and refactoring for takeover via web backdoor
2011-06-08 14:16:53 +00:00
Bernardo Damele
cce3208b35
Cleanup
2011-06-08 14:15:34 +00:00
Bernardo Damele
7da3d8dbd1
minor layout adjustment
2011-06-08 13:01:33 +00:00
Bernardo Damele
161ece5587
Rephrase
2011-06-08 11:33:45 +00:00
Bernardo Damele
6d2c97d06f
updated thanks file
2011-06-08 10:44:55 +00:00
Miroslav Stampar
f65abdaae3
added switch --cookie-del by request
2011-06-08 08:27:24 +00:00
Miroslav Stampar
4eeeb3655e
asking and skipping to the next google result page if no usable links found
2011-06-07 23:24:17 +00:00
Miroslav Stampar
1c633b7351
i am tired of pressing hundred times Ctrl+C in testing phase if --batch is specified
2011-06-07 22:14:18 +00:00
Miroslav Stampar
75c12c5edb
fix for a bug reported by cclements@flatearth.net (TypeError: argument of type 'NoneType' is not iterable)
2011-06-07 21:46:49 +00:00
Miroslav Stampar
e7e23d1b79
fix for a Ctrl+C bug reported by nightman@email.de
2011-06-07 17:16:01 +00:00
Miroslav Stampar
26062ec71e
minor update
2011-06-07 15:13:51 +00:00
Miroslav Stampar
f34b395c65
fixing typo
2011-06-07 14:58:22 +00:00
Miroslav Stampar
50dde39e68
minor update
2011-06-07 10:32:18 +00:00
Miroslav Stampar
e9bf768f23
more refactoring
2011-06-07 10:08:12 +00:00
Miroslav Stampar
7a3cc38e3c
refactoring and stabilization of multithreading
2011-06-07 09:50:00 +00:00
Miroslav Stampar
5f7858455d
fix for a bug reported by l0rda@l0rda.biz
2011-06-07 05:57:21 +00:00
Miroslav Stampar
22948135ec
this is totally unnecessary but one more byte is squeezed out
2011-06-06 18:16:45 +00:00
Miroslav Stampar
07f6a9cae6
three more bytes squeezed out
2011-06-06 18:08:36 +00:00
Miroslav Stampar
e5cecd3afd
minor update
2011-06-06 18:06:00 +00:00
Miroslav Stampar
59e562f611
well this was interesting :)
2011-06-06 18:03:21 +00:00
Miroslav Stampar
b0c9c66672
more improvement (1000 bytes!)
2011-06-06 14:53:50 +00:00
Miroslav Stampar
702e8a1be8
further improvement
2011-06-06 14:19:57 +00:00
Miroslav Stampar
5b932941fe
shortening PHP backdoor
2011-06-06 14:11:09 +00:00
Miroslav Stampar
03c3f83893
minor fix
2011-06-06 13:34:49 +00:00
Miroslav Stampar
89a7516c35
bug fix
2011-06-06 09:55:22 +00:00
Miroslav Stampar
24ed99e5a3
fix for a bug reported by aboynes@gmail.com
2011-06-06 08:50:48 +00:00
Miroslav Stampar
97d8c60c3f
better language
2011-06-03 15:58:19 +00:00
Miroslav Stampar
0a620bf322
more info to the user
2011-06-03 15:43:50 +00:00
Miroslav Stampar
8c80413c52
well, important fix for blind based cases (especially OR ones)
2011-06-03 15:29:22 +00:00
Miroslav Stampar
f27181c628
minor improvement for blind based injections with reflected values
2011-06-03 14:41:36 +00:00
Miroslav Stampar
e9eafc2e94
minor update
2011-06-03 14:13:22 +00:00
Miroslav Stampar
64a862ed58
minor usability update
2011-06-03 14:04:02 +00:00
Miroslav Stampar
faf7814869
fix for a fuzz "bug" reported by daniele.rivetti@yahoo.com
2011-06-03 11:01:26 +00:00
Miroslav Stampar
08d6bb4f23
minor fix
2011-06-02 22:13:31 +00:00
Miroslav Stampar
8aa5625cd0
proper fix related to the last commit
2011-06-01 23:00:18 +00:00
Miroslav Stampar
fd57aae779
bug fix (until this moment we had UNION unfunctional for MSSQL)
2011-06-01 22:47:54 +00:00
Miroslav Stampar
fc96764f80
minor bug fix ("trimmed" error message was shown for empty cases too because u'' or None == None)
2011-06-01 22:06:06 +00:00
Miroslav Stampar
091c174bc4
better language
2011-06-01 08:30:06 +00:00
Miroslav Stampar
63145236b9
minor fix
2011-05-31 21:53:29 +00:00
Miroslav Stampar
0b875b160f
cosmetics
2011-05-31 20:57:29 +00:00
Miroslav Stampar
3fa8e1db72
better language
2011-05-31 15:45:54 +00:00
Miroslav Stampar
4bb9754dfe
using --dump for msaccess with -C switch was for some reason pain in the ass (you had to do the brute forcing again and again). now -C forces the result in those cases
2011-05-30 23:34:48 +00:00
Miroslav Stampar
42100e0e5b
big bug fix
2011-05-30 23:15:29 +00:00
Miroslav Stampar
9600556dae
better language
2011-05-30 23:04:49 +00:00
Miroslav Stampar
b7088440c2
better sentence
2011-05-30 22:47:17 +00:00
Miroslav Stampar
3c12799ff0
minor improvement
2011-05-30 20:34:34 +00:00
Miroslav Stampar
89559d1b0a
better regex and now after we have that automatic switch off for reflective removal mechanism it's not so important to change it
2011-05-30 20:18:30 +00:00
Miroslav Stampar
23cec012d1
fix for that unhandled (after program exit) KeyboardInterrupt
2011-05-30 15:13:47 +00:00
Miroslav Stampar
b79dae6e95
minor update
2011-05-30 14:49:03 +00:00
Miroslav Stampar
20988e58ed
warp 5 mr spock :)
2011-05-30 09:46:32 +00:00
Miroslav Stampar
001cbff2a9
speed up of 2 times for partial union technique
2011-05-30 09:07:48 +00:00
Miroslav Stampar
97820949f5
minor update
2011-05-30 08:33:01 +00:00
Miroslav Stampar
d5ede6afb4
fix for a dirty reading issue reported by skysbsb@gmail.com (IndexError: list index out of range)
2011-05-30 06:38:44 +00:00
Miroslav Stampar
23d7820de7
minor update
2011-05-29 23:56:41 +00:00
Miroslav Stampar
6fd8602f01
minor update
2011-05-29 23:33:34 +00:00
Miroslav Stampar
86455ceb9c
implementation of multithreading for UNION and ERROR techniques
2011-05-29 23:17:50 +00:00
Miroslav Stampar
d51efa679d
typo update
2011-05-29 06:26:28 +00:00
Miroslav Stampar
f848cc779e
adding legal disclaimer as latest situation (these days news headlines) seems out of control
2011-05-28 18:54:14 +00:00
Miroslav Stampar
a5a70f0895
minor update
2011-05-28 18:21:03 +00:00
Miroslav Stampar
ecbeecdccf
minor refactoring
2011-05-28 18:11:56 +00:00
Miroslav Stampar
eb9b84d1da
type correction
2011-05-28 17:53:05 +00:00
Miroslav Stampar
03ef53f00a
update regarding mysql function resolution and versionedkeywords
2011-05-28 17:34:43 +00:00
Miroslav Stampar
bfd923fe29
minor update
2011-05-28 16:16:20 +00:00
Miroslav Stampar
25f3143d92
minor update (to be concise with between)
2011-05-28 16:04:49 +00:00
Miroslav Stampar
b079a543ee
minor update
2011-05-28 16:03:36 +00:00
Miroslav Stampar
7578795c96
adding one more tamper script
2011-05-28 16:02:14 +00:00
Miroslav Stampar
fef9a015da
minor update
2011-05-28 15:44:24 +00:00
Miroslav Stampar
39f131162f
adding very useful tampering script
2011-05-28 15:42:47 +00:00
Miroslav Stampar
95dea1fbf9
sharp tuning UNION tests even more
2011-05-28 08:06:19 +00:00
Miroslav Stampar
74cc974fa7
cosmetics
2011-05-28 06:44:17 +00:00
Miroslav Stampar
6e8b689596
removing leftover
2011-05-28 06:40:44 +00:00
Miroslav Stampar
c11ea35d53
adding some user input for "refreshing" cases (like redirect ones)
2011-05-27 22:42:23 +00:00
Miroslav Stampar
cf69809c3c
minor update
2011-05-27 16:26:00 +00:00
Miroslav Stampar
8227298057
user friendliness uber 9000
2011-05-27 08:30:52 +00:00
Miroslav Stampar
a8b58afdb2
minor update
2011-05-27 08:21:02 +00:00
Miroslav Stampar
48f52d7697
minor beautification
2011-05-27 08:16:14 +00:00
Miroslav Stampar
9f6b70f3f9
update
2011-05-26 22:45:33 +00:00
Miroslav Stampar
61b960f65f
minor update related to the last one
2011-05-26 22:05:10 +00:00
Miroslav Stampar
45caadbd4a
important update - finally found what was causing headache for UNION payloads in noticeable number of cases
2011-05-26 21:54:19 +00:00
Miroslav Stampar
97bd5355dd
minor update
2011-05-26 21:18:55 +00:00
Miroslav Stampar
5d56e89cf5
minor update
2011-05-26 21:08:46 +00:00
Miroslav Stampar
06108b6da6
minor update related to the last commit
2011-05-26 20:58:24 +00:00
Miroslav Stampar
4f46a5ab63
minor usability enhancement regarding warning for --text-only switch
2011-05-26 20:48:18 +00:00
Miroslav Stampar
ff030e4d24
minor cleanup of the leftover
2011-05-26 17:37:24 +00:00
Miroslav Stampar
bf2b58ba82
minor update
2011-05-26 15:23:28 +00:00
Miroslav Stampar
79f0b3a92a
adding support for --start and --stop for __pivotDumpTable
2011-05-26 15:16:57 +00:00
Miroslav Stampar
b6fe5b12a4
adding --schema to the wizard/Basic as it looks like a cool thingy to put there
2011-05-26 14:30:05 +00:00
Miroslav Stampar
46ceb14f37
update of doc/THANKS
2011-05-26 13:49:42 +00:00
Miroslav Stampar
4f2c999146
fix for a bug reported by mail@8dh.de (UnicodeDecodeError: requestMsg += "\n%s" % requestHeaders)
2011-05-26 13:47:20 +00:00
Miroslav Stampar
9077eadf23
update of doc/THANKS
2011-05-26 08:22:52 +00:00
Miroslav Stampar
a397baa89a
fix for a bug reported by viniciusmaxdaloop@gmail.com and few related patches
2011-05-26 08:17:21 +00:00
Miroslav Stampar
f3ed61af5f
bug fix when using inference and kb.pageEncoding is None (like in binary cases)
2011-05-25 21:12:12 +00:00
Miroslav Stampar
5369657cd5
fix for cases with retrieved binary files (preventing difflib nagging around comparison)
2011-05-25 20:54:30 +00:00
Miroslav Stampar
a1fd2898a0
added friendly tip message for url encoding GET and POST payloads
2011-05-25 11:10:52 +00:00
Miroslav Stampar
0e480a9921
adding SYS to the ORACLE_SYSTEM_DBS
2011-05-25 10:55:47 +00:00
Miroslav Stampar
2f456bee75
minor beautification
2011-05-25 08:14:39 +00:00
Miroslav Stampar
8b7a3c5a6b
making it easier for totally dummy users
2011-05-24 17:24:01 +00:00
Miroslav Stampar
bec2c04671
helping dummy users
2011-05-24 17:15:25 +00:00
Miroslav Stampar
a3466ff79c
serving everything for the users
2011-05-24 16:34:08 +00:00
Miroslav Stampar
69eb173eca
minor just in case patch
2011-05-24 15:07:37 +00:00
Miroslav Stampar
0072c3af8e
fix for a bug reported by aboynes@gmail.com (for elt in self.a)
2011-05-24 15:03:21 +00:00
Miroslav Stampar
f774d8fea0
proper Tor settings (reverted r3915 and implemented it the right way)
2011-05-24 11:06:58 +00:00
Miroslav Stampar
0486d1cdaa
minor module update
2011-05-24 10:32:21 +00:00
Miroslav Stampar
915c206e3d
minor fix for socks proxy issues
2011-05-24 09:47:10 +00:00
Miroslav Stampar
0baf931669
real generic comment is "-- " not "--" (MySQL doesn't support "--")
2011-05-24 09:16:21 +00:00
Miroslav Stampar
ad25bcc2be
better way for dealing with relative paths
2011-05-24 05:26:51 +00:00
Miroslav Stampar
a536bf210f
improved redirection mechanism
2011-05-23 23:20:03 +00:00
Miroslav Stampar
128a012121
this was causing that --suffix trouble
2011-05-23 19:59:07 +00:00
Miroslav Stampar
bfe8e51b7c
minor fix for retrieving stuff like "SELECT * FROM testdb..users"
2011-05-23 19:45:40 +00:00
Miroslav Stampar
1067d43f14
minor update
2011-05-23 19:16:29 +00:00
Miroslav Stampar
2b12b18357
incorporating metasploit patch from oliver.kuckertz@mologie.de
2011-05-23 15:27:10 +00:00
Miroslav Stampar
4542d4535f
minor beautification
2011-05-23 14:28:05 +00:00
Miroslav Stampar
31b48ec11c
removing space left
2011-05-23 14:18:33 +00:00
Miroslav Stampar
0ed03d474f
now supporting "blank tables" - schema of the table will be preserved, even if it's empty - especially nice feature for --replicate
2011-05-23 11:09:44 +00:00
Miroslav Stampar
868fbe370b
minor beautification
2011-05-23 10:39:58 +00:00
Miroslav Stampar
171a4c389b
added MySQL >=4.1 <=5.0 error based WHERE/HAVING payload
2011-05-23 06:24:45 +00:00
Miroslav Stampar
fb23beef6f
most elegant way i could think of to deal with "collation incompatibilities" issue on some MySQL/UNION cases (affected about 5% of all targets tested)
2011-05-22 19:14:36 +00:00
Miroslav Stampar
4fdb6ac9b9
adding useful info
2011-05-22 15:30:19 +00:00
Miroslav Stampar
48c20a62ac
minor nag fix
2011-05-22 15:08:55 +00:00
Miroslav Stampar
40971aca94
fixing nasty bug caused by retrying counter
2011-05-22 10:59:56 +00:00
Miroslav Stampar
712e238f33
another minor fix
2011-05-22 10:29:25 +00:00
Miroslav Stampar
2795aeff34
minor fix
2011-05-22 10:27:45 +00:00
Miroslav Stampar
806e898694
no more CRITICAL drop outs in test mode - lots of reports were related to this
2011-05-22 10:21:49 +00:00
Miroslav Stampar
7b52bbe3fb
reverting that ignoreTimeout for --tables (because of this and that)
2011-05-22 09:59:19 +00:00
Miroslav Stampar
9b2623514a
one bug fix for Host header (value should be without port number); one improvement for --tables - when no tables ask user if he wants to brute force them; one tweak - adding kb.ignoreTimeout for --tables
2011-05-22 09:48:46 +00:00
Miroslav Stampar
2ea613b170
type correction and adding global flag kb.ignoreTimeout which could be useful
2011-05-22 08:24:13 +00:00
Miroslav Stampar
27f0e73cc9
refactoring of 'target' flag in connect.py
2011-05-22 07:46:09 +00:00
Miroslav Stampar
a58aaf2e1a
better format for results file (easier for sorting when lots of files)
2011-05-22 07:02:36 +00:00
Miroslav Stampar
25fff8c135
changes in handling --tor (using SOCKS instead of HTTP for handling Tor - more standard way; doesn't require proxy bundle; fixes problems with default proxy ports on Win/Linux)
2011-05-21 11:46:57 +00:00
Miroslav Stampar
939e6541d0
far safer way for dealing with error-based payloads on MySQL (no timeouts with .CHARACTER_SETS on testing platforms versus when used .TABLES)
2011-05-19 23:36:51 +00:00
Miroslav Stampar
126cdf9e19
minor info update
2011-05-19 23:28:27 +00:00
Miroslav Stampar
a034462c31
fixing annoying timeouts for basic DBMS check (reference: http://dev.mysql.com/doc/refman/5.0/en/date-and-time-functions.html#function_timestampadd )
2011-05-19 23:03:00 +00:00
Miroslav Stampar
5a979f7667
minor bug fix for empty colList; also added "do you want to use LIKE" (LIKE is default) question when -C used
2011-05-19 17:35:33 +00:00
Miroslav Stampar
9e5856caf8
improvement for recognition of scalar vs multiple-row commands
2011-05-19 16:45:05 +00:00
Miroslav Stampar
db72428765
minor update
2011-05-19 15:57:29 +00:00
Miroslav Stampar
f40c6b2ce7
added --cookie for maskSensitiveData too
2011-05-19 15:42:59 +00:00
Miroslav Stampar
bd1b07fbc2
one more parameter replace payload for MySQL and rising level of GENERATE_SERIES for PostgreSQL
2011-05-19 06:32:23 +00:00
Miroslav Stampar
7f086916c0
decent parameter replace payload for PostgreSQL (GENERATE_SERIES)
2011-05-18 23:40:42 +00:00
Miroslav Stampar
e58d6d2e00
removing (CBRT(LN(0)) because it's nothing special compared to standard 1/0; also, removing parameter replacement with returned value 1 as it doesn't have much sense in comparison to origvalue one (which is far more stable and usable)
2011-05-18 23:20:02 +00:00
Miroslav Stampar
fe50d09cc8
added new payload for PostgreSQL (parameter replace)
2011-05-18 23:01:41 +00:00
Miroslav Stampar
9832fc42d4
minor improvement for --tamper (now standard tamper scripts can be used like --tamper=randomcase)
2011-05-18 21:47:40 +00:00
Miroslav Stampar
3048e9f710
minor refactoring
2011-05-17 23:03:31 +00:00
Miroslav Stampar
cc07e5dc97
added --charset option to force charset encoding of the retrieved data (e.g. when the backend collation is different than the current web page charset) as requested by devon.mitchell1988@yahoo.com
2011-05-17 22:55:22 +00:00
Miroslav Stampar
dfe81cc66f
minor yielding
2011-05-16 20:14:10 +00:00
Miroslav Stampar
a5ad4621c9
minor refactoring
2011-05-16 20:09:12 +00:00
Miroslav Stampar
ba1df457ab
fix for a charset euc_tw reported by devon.mitchell1988@yahoo.com
2011-05-16 19:26:58 +00:00
Miroslav Stampar
6ba9dea640
just in case for trimmed output
2011-05-16 06:17:37 +00:00
Miroslav Stampar
d2221e4604
fix for a minor "retrieved" cosmetic issue in partial union technique reported by Devon Mitchell (retrieved: "information_schema","COLUMNS</title><...)
2011-05-16 00:23:50 +00:00
Miroslav Stampar
faa74cd2bc
introducing results file for multiple target mode
2011-05-15 22:21:38 +00:00
Miroslav Stampar
90e84c9a6d
removing xmlcharrefreplace error handler as it seems that it wasn't such a good idea at the end
2011-05-15 21:43:38 +00:00
Miroslav Stampar
c3bb5a03e1
minor improvement
2011-05-14 20:09:37 +00:00
Miroslav Stampar
3484a4426b
fix for a bug reported by itxx@qq.com (TypeError: encode() takes no keyword arguments)
2011-05-14 19:57:28 +00:00
Miroslav Stampar
053c245114
few minor fixes
2011-05-13 09:56:12 +00:00
Miroslav Stampar
a7d7be5ce0
bug fix ('Host' header was being set to the conf.hostname for all getPages causing problems in some cases when retrieved page was not coming from that same Host)
2011-05-13 01:01:53 +00:00
Miroslav Stampar
f11d5c91e3
minor update so that only one DNS request per scan is being done (before this commit there were two)
2011-05-12 14:32:39 +00:00
Miroslav Stampar
70688fb8b5
minor enhancement for dumping 'None' values (proper way should be empty string because None is too pythonic)
2011-05-12 12:00:17 +00:00
Miroslav Stampar
c64eb38a8b
same thing as for the last commit, but for error technique this time
2011-05-12 11:52:18 +00:00
Miroslav Stampar
84a7e5ffb9
"unfix" for r3172 which was causing "AttributeError: 'list' object has no attribute 'isdigit'" because of change of appereance
2011-05-12 11:36:02 +00:00
Miroslav Stampar
0b2da2f9f5
minor beautification for --tor switch
2011-05-12 05:46:17 +00:00
Miroslav Stampar
e05a9c0554
i was probably very tired or very stupid to do this
2011-05-11 13:13:46 +00:00
Miroslav Stampar
2ab9e30f7a
bug fix
2011-05-11 12:54:33 +00:00
Miroslav Stampar
4efc284b83
adding more info for --passwords
2011-05-11 12:35:32 +00:00
Miroslav Stampar
48ac9911c0
more graceful fix related to the last commit
2011-05-11 09:42:35 +00:00
Miroslav Stampar
402c623119
minor fix
2011-05-11 09:40:11 +00:00
Miroslav Stampar
53065ee1fb
adding ordered set for kb.targetUrls (now the order of appereance in multiple targets mode will be respected)
2011-05-11 08:55:48 +00:00
Miroslav Stampar
5ee07b90b9
added -m switch for bulk loading multiple targets
2011-05-11 08:46:40 +00:00
Miroslav Stampar
120b0d756e
unfix
2011-05-10 21:33:06 +00:00
Miroslav Stampar
6b66fce72c
minor fix
2011-05-10 20:52:43 +00:00
Miroslav Stampar
192c685bc8
changing conf attribute to a more proper name
2011-05-10 20:48:34 +00:00
Miroslav Stampar
deae534ee7
minor refactoring
2011-05-10 20:44:36 +00:00
Bernardo Damele
97bc816aeb
layout
2011-05-10 16:24:09 +00:00
Bernardo Damele
b5f090cc4f
Minor bug fix
2011-05-10 15:48:48 +00:00
Bernardo Damele
3a8309c4b0
Major bug fix to detect UNION query technique and various improvements to parsing and using of --union-char and --union-cols switches
2011-05-10 15:34:54 +00:00
Miroslav Stampar
707edc7b1a
fix for a bug (previously --dbms="mysql 4" was ignored and abruptly terminated while the mechanism was here all along)
2011-05-10 13:28:07 +00:00
Miroslav Stampar
1dea609019
fix for a bug reported by David (UnicodeDecodeError: url = url + '?' + query)
2011-05-10 12:51:37 +00:00
Miroslav Stampar
a64407d9db
minor bug fix for multithreading and lots of connection retries
2011-05-10 12:40:01 +00:00
Miroslav Stampar
22a1870c2c
adding some constraining to number of used threads on brute force switches together with a warning in case of connection exception(s) with --threads>1
2011-05-10 12:32:07 +00:00
Bernardo Damele
49b925772b
Minor update
2011-05-10 10:56:06 +00:00
Miroslav Stampar
b713b18fd2
minor fix for a bug spotted on Sybase
2011-05-09 16:09:18 +00:00
Bernardo Damele
ac74557614
Minor adjustment for --dump-all
2011-05-08 10:25:40 +00:00
Miroslav Stampar
ec4d9178f8
minor update related to the previous commit
2011-05-08 06:28:58 +00:00
Miroslav Stampar
4d6e7c738c
minor update
2011-05-08 06:17:43 +00:00
Bernardo Damele
356037ca22
cosmetics
2011-05-08 02:11:34 +00:00
Bernardo Damele
9955483052
Major improvement for --dump.
...
Minor improvement for --dump-all.
Minor bug fix for infinite loop
2011-05-08 02:08:18 +00:00
Bernardo Damele
8179fd63c0
Minor fix
2011-05-07 23:48:03 +00:00
Bernardo Damele
d3589493d1
Temporary fix for bug reported by ultramegaman (infinite loop)
2011-05-07 23:28:59 +00:00
Bernardo Damele
6e784e766b
Minor bug fix
2011-05-07 21:20:47 +00:00
Bernardo Damele
6653907700
forgot in last commit
2011-05-07 21:13:56 +00:00
Bernardo Damele
1151af52bb
More fix for save/resume of --technique
2011-05-07 21:08:14 +00:00
Bernardo Damele
28a4ae8eaf
Minor improvement to cleanup script
2011-05-06 13:53:10 +00:00
Miroslav Stampar
d2a71d647b
minor update
2011-05-06 13:38:58 +00:00
Miroslav Stampar
9652efa995
minor update
2011-05-06 13:34:03 +00:00
Miroslav Stampar
079ddf84b2
updating FAQ
2011-05-06 11:19:49 +00:00
Bernardo Damele
aae140080e
SVN roll back, DB2 patch will be recommitted after testing:
...
$ svn merge https://svn.sqlmap.org/sqlmap/trunk/sqlmap@HEAD https://svn.sqlmap.org/sqlmap/trunk/sqlmap@3847 .
2011-05-06 10:27:43 +00:00
Miroslav Stampar
42bca80968
removing blank lines and adding newline at the end of files
2011-05-06 09:35:53 +00:00
Miroslav Stampar
6e392b6054
applying contributed patch for DB2
2011-05-06 09:30:39 +00:00
Bernardo Damele
2d8408c885
More fix for --technique resume
2011-05-05 16:38:46 +00:00
Bernardo Damele
e96a533a04
Bug fix to resume of --technique
2011-05-05 15:18:33 +00:00
Bernardo Damele
eea96c5b8d
code cleanup
2011-05-05 08:50:18 +00:00
Miroslav Stampar
b12aa8a56f
added mime type octet to README.pdf
2011-05-05 08:17:23 +00:00
Miroslav Stampar
b324b99f6e
minor update of warning message
2011-05-04 10:41:08 +00:00
Miroslav Stampar
83fac3f6d9
fix for proper MSSQL error chunking in some cases (not screwing output length toward lower values at chunk phase)
2011-05-03 21:12:51 +00:00
Miroslav Stampar
e6f010734e
minor fix for cases when the retrieved output is safe encoded (like for --os-shell)
2011-05-03 16:14:03 +00:00
Miroslav Stampar
4d4e3802e4
decoding of chars for --os-shell
2011-05-03 15:31:12 +00:00
Bernardo Damele
2976ed7e90
Updated user's manual, added details about URI injection
2011-05-03 14:47:01 +00:00
Bernardo Damele
dac59a55bc
leftover
2011-05-03 14:14:39 +00:00
Bernardo Damele
c58dc4a6d8
isDbmsWithin() must stay like this, no getIdentifiedDbms() in there
2011-05-03 14:13:45 +00:00
Miroslav Stampar
742b0ef76e
major improvement of ERROR data retrieval on MSSQL
2011-05-03 13:25:20 +00:00
Miroslav Stampar
2a7838928e
minor fancier --replicate update
2011-05-03 11:48:04 +00:00
Miroslav Stampar
b202d73b46
bug fix for MSSQL identificators which were starting with d, b, o and . Thing is that .lstrip strips all occurances of the given chars :) (spotted ancidentally)
2011-05-03 11:09:30 +00:00
Bernardo Damele
b2f6ce9716
updated documentation
2011-05-03 10:57:55 +00:00
Miroslav Stampar
1840b0e43b
fix for a bug reported by k1971@live.co.uk (OperationalError: unknown database dbo)
2011-05-03 10:22:38 +00:00
Miroslav Stampar
1e6c2fea74
update regarding warning for --random-agent during connection timeout in connection test phase
2011-05-03 10:05:42 +00:00
Miroslav Stampar
eceb5eca7b
fix for --file-read on MSSQL for error technique (again that unpacking was causing problems); also reverting that check for file paths as one user mentioned that network paths are also possible for usage on Windows machines (e.g. \\bla\bla)
2011-05-02 21:55:06 +00:00
Bernardo Damele
6cff3e97f4
cosmetics
2011-05-02 21:48:08 +00:00
Miroslav Stampar
06498796b9
minor cosmetics
2011-05-02 20:51:53 +00:00
Miroslav Stampar
b327a78522
minor minor update of the last commit
2011-05-02 19:24:49 +00:00
Miroslav Stampar
0bb7d715a7
more user friendliness/handiness for users which mix Linux and Windows paths where they shouldn't do that
2011-05-02 19:18:28 +00:00
Miroslav Stampar
845618934d
update of doc/THANKS
2011-05-02 18:20:37 +00:00
Miroslav Stampar
5e9620198c
fix for a privately reported bug ("AttributeError: item is disabled")
2011-05-02 18:18:04 +00:00
Miroslav Stampar
93dee30895
better fix for the previous commit
2011-05-02 13:34:55 +00:00
Miroslav Stampar
20ad1c1f2f
minor update to not confuse users when using -o
2011-05-02 13:24:35 +00:00
Miroslav Stampar
f8c3086d15
minor minor update
2011-05-02 12:37:54 +00:00
Miroslav Stampar
098f53d57a
patch for a problem reported by m.martin2311@yahoo.com (unknown charset 'is0-8859-1')
2011-05-02 12:34:35 +00:00
Bernardo Damele
ac2550535c
Proper fix for --technique=U bug
2011-05-01 23:42:41 +00:00
Miroslav Stampar
8e8886cd20
minor improvement for --sql-shell/--sql-query (when non-SELECT default is N for retrieve data output which automatically does STACKED injection)
2011-05-01 21:41:14 +00:00
Miroslav Stampar
900ee0ff93
fix for a major bug reported by k1971@live.co.uk (1..9 99..)
2011-05-01 15:47:00 +00:00
Miroslav Stampar
494503b334
proper way to deal with generic cases
2011-05-01 08:04:08 +00:00
Miroslav Stampar
fcd69ba9c7
fix for a --technique=U
2011-05-01 07:37:22 +00:00
Bernardo Damele
ebe631ea57
doc update
2011-05-01 00:43:42 +00:00
Bernardo Damele
64bb480414
Do not raise otherwise it won't work with --schema
2011-04-30 23:20:16 +00:00
Miroslav Stampar
41fc9f9d54
fix for an issue reported by andrew.gecse@upcmail.hu (unknown web page charset 'hungarian-iso-8859-2')
2011-04-30 22:41:54 +00:00
Bernardo Damele
d5eeb91b35
Aligned Sybase and MaxDB to recent enhancements to --dbs, --tables and --columns
2011-04-30 22:11:36 +00:00
Bernardo Damele
b31b861d7b
Major rewrote of --columns: now it accepts -D only (enumerate all tables' columns of a specific database), -D and -T (enumerate all columns of a specific database's table), -T (enumerate all columns of a current database's table), etc.
2011-04-30 22:10:27 +00:00
Bernardo Damele
284c69a686
Improved --tables for MSSQL too, like r3798
2011-04-30 22:05:02 +00:00
Bernardo Damele
aeb149db22
Proper ordering of enumeration methods, consistent with the others enumeration classes
2011-04-30 22:04:08 +00:00
Bernardo Damele
955dbc85e7
Minor variable rename
2011-04-30 15:29:59 +00:00
Bernardo Damele
cb9b9c4204
Code refactoring and improvements to --dbs and --tables: now --tables accepts also -D CD as an alias for Current Database and as usual multiple database comma-separated are supported too
2011-04-30 15:29:19 +00:00
Bernardo Damele
b3a0424269
More Backend class method usage refactoring
2011-04-30 15:24:15 +00:00
Bernardo Damele
00f14bec5f
layout adjustment
2011-04-30 15:22:33 +00:00
Bernardo Damele
9a4ae7d9e2
More code refactoring of Backend class methods used
2011-04-30 14:54:29 +00:00
Bernardo Damele
2f2758b033
Long form contributor name
2011-04-30 14:51:06 +00:00
Bernardo Damele
36a9ddaacc
Minor bug fixes and code restyling for --privileges and --passwords
2011-04-30 14:50:27 +00:00
Bernardo Damele
f56d135438
Minor code restyling
2011-04-30 13:20:05 +00:00
Miroslav Stampar
983546d6bf
proper fix
2011-04-30 07:01:21 +00:00
Bernardo Damele
1a052245a6
duplicate code
2011-04-30 00:25:15 +00:00
Bernardo Damele
a5968fff3e
Added --count switch to count the number of entries for a specific table (when -T is provided), all database's tables (when only -D is provided) or all databases' tables when neither -D nor -T are provided
2011-04-30 00:22:22 +00:00
Bernardo Damele
529595fd85
Moved method below
2011-04-29 22:37:43 +00:00
Bernardo Damele
956e75e2b5
Minor adjustment to --mobile.
...
Bug fix to --random-agent.
2011-04-29 21:50:48 +00:00
Bernardo Damele
14bf6abb7e
Minor layout adjustment
2011-04-29 21:40:48 +00:00
Bernardo Damele
f449688f93
Proper resume of --schema data when calling with --columns switch, minor fixes too
2011-04-29 21:17:59 +00:00
Bernardo Damele
a23ca952e4
Actually brute-force switches make more sense just after their "normal" version. Also, getSchema() method is preferably to be called before getColumns(), see next commit for reason
2011-04-29 21:09:07 +00:00
Miroslav Stampar
46f96f3c4c
removing Kindle from list as it's not really a smartphone
2011-04-29 19:32:30 +00:00
Miroslav Stampar
11124b21f9
implemented --mobile switch
2011-04-29 19:27:23 +00:00
Miroslav Stampar
b299912de4
fix for a bug reported by ahmed@isecur1ty.org (UnicodeDecodeError: 'ascii' codec can't decode byte 0x84 in position 396: ordinal not in range(128)) for multipartpost
2011-04-29 16:56:02 +00:00
Miroslav Stampar
6bb4dce3aa
minor refactoring
2011-04-29 15:22:32 +00:00
Miroslav Stampar
a2bb0d72e8
fix for a bug reported by rdsears@mtu.edu (TypeError: expected string or buffer)
2011-04-29 14:40:28 +00:00
Miroslav Stampar
a6015b59df
fix for a bug reported by jaccovantuijl@gmail.com (entries = zip(*[entries[colName] for colName in colList]))
2011-04-29 14:33:47 +00:00
Bernardo Damele
9927f5a7db
Let --schema work also for Sybase and MaxDB
2011-04-29 00:02:28 +00:00
Bernardo Damele
edac0b2558
Added switch --schema to enumerate DBMS schema and now --columns does not require a mandatory table (-T) anymore, instead it will act as an alias for --schema
2011-04-28 23:59:00 +00:00
Bernardo Damele
d3ed3268c3
minor adjustments
2011-04-28 21:17:06 +00:00
Bernardo Damele
8e63e1b70d
more people to thanks
2011-04-28 21:15:15 +00:00
Bernardo Damele
3e66dae103
as we don't use UPX anymore..
2011-04-28 20:54:21 +00:00
Bernardo Damele
441c288dd9
cosmeticados
2011-04-25 00:36:09 +00:00
Bernardo Damele
98f9f3e774
Minor bug fix in local shellcodeexec for Windows path
2011-04-25 00:03:12 +00:00
Bernardo Damele
e35f25b2cb
Major recode of --os-pwn functionality. Now the Metasploit shellcode can not be run as a Metasploit generated payload stager anymore. Instead it can be run on the target system either via sys_bineval() (as it was before, anti-forensics mode, all the same) or via shellcodeexec executable. Advantages are that:
...
* It is stealthier as the shellcode itself does not touch the filesystem, it's an argument passed to shellcodeexec at runtime.
* shellcodeexec is not (yet) recognized as malicious by any (Avast excluded) AV product.
* shellcodeexec binary size is significantly smaller than a Metasploit payload stager (even when packed with UPX).
* UPX now is not needed anymore, so sqlmap package is also way smaller and less likely to be detected itself as malicious by your AV software.
shellcodeexec source code, compilation files and binaries are in extra/shellcodeexec/ folder now - copied over from https://github.com/inquisb/shellcodeexec .
Minor code refactoring.
2011-04-24 23:01:21 +00:00
Bernardo Damele
d0a534dee5
Do not even prompt for ICMP tunnel if the target OS is not Windows
2011-04-23 21:57:07 +00:00
Bernardo Damele
d0dff82ce0
Minor code refactoring relating set/get back-end DBMS operating system and minor bug fix to properly enforce OS value with --os switch
2011-04-23 16:25:09 +00:00
Miroslav Stampar
75142b383d
huge speed up (4x times faster)
2011-04-22 21:00:42 +00:00
Miroslav Stampar
f88aa4b165
implemented suppressResumeInfo mechanism (huge slowdown on large tables)
2011-04-22 19:58:10 +00:00
Miroslav Stampar
493b9adf8e
speed up of resume values (compiled regexes used)
2011-04-22 19:27:41 +00:00
Miroslav Stampar
7b3b9e6a87
it seems that this was indeed not meant to be here
2011-04-22 15:07:09 +00:00
Miroslav Stampar
304500a2e8
implemented checkFalsePositives method (simple Turing like tests)
2011-04-22 12:24:16 +00:00
Bernardo Damele
7df954dd9f
paranoy
2011-04-21 23:41:25 +00:00
Miroslav Stampar
0764c4c752
parenthesis were missing; banning OR NOT from payloads
2011-04-21 23:32:53 +00:00
Miroslav Stampar
41924a6ead
fix for a bug reported by saccurso@skygear.com.ar (UnicodeDecodeError: 'ascii' codec can't decode byte 0xe9 in position 0: ordinal
...
not in range(128))
2011-04-21 23:17:16 +00:00
Bernardo Damele
1d61611145
leftover
2011-04-21 22:46:43 +00:00
Bernardo Damele
f3088079c0
error message adjustment
2011-04-21 22:31:02 +00:00
Bernardo Damele
eabb5a2ba7
More adjustments to the error message when no sql injections are detected
2011-04-21 22:04:20 +00:00
Bernardo Damele
6d07dddf60
updated doc and minor layout adjustments
2011-04-21 21:53:35 +00:00
Bernardo Damele
06a00fe85e
For development version, print also the revision number in the banner
2011-04-21 21:34:57 +00:00
Bernardo Damele
770b1523ff
More verbose output when no SQL injections are detected
2011-04-21 21:31:16 +00:00
Bernardo Damele
edc2d75702
Cosmetics and major bug fix
2011-04-21 21:15:23 +00:00
Bernardo Damele
870f773d70
In some old versions of MySQL (perhaps others DBMS too) the NOT clause is not supported, hence we need also OR tests without NOT - tested and works like this
2011-04-21 20:36:50 +00:00
Bernardo Damele
d2f102f5a1
cosmetics
2011-04-21 20:21:37 +00:00
Miroslav Stampar
148fb26301
quick fix
2011-04-21 17:34:26 +00:00
Miroslav Stampar
e181d5412e
fix for a bug reported by aboynes@gmail.com (@@datadir not available on MySQL 4)
2011-04-21 17:33:07 +00:00
Miroslav Stampar
bd4fbb3251
fix for a bug reported by l0rda@l0rda.biz (TypeError: cannot concatenate 'str' and 'NoneType' objects)
2011-04-21 14:53:02 +00:00
Bernardo Damele
b667c50588
store/resume info on xp_cmd available in session file
2011-04-21 14:25:04 +00:00
Miroslav Stampar
930872cf3b
fix
2011-04-21 14:20:09 +00:00
Bernardo Damele
a313df4d37
Allow user to force temporary folder with --tmp-path even if it has been saved one in the session file
2011-04-21 14:05:37 +00:00
Bernardo Damele
fbe5ba5394
cosmetics
2011-04-21 10:54:12 +00:00
Miroslav Stampar
e1a8d268d8
fix for UPX linux/macos
2011-04-21 10:52:34 +00:00
Bernardo Damele
8d8fc2bbd8
cosmetics
2011-04-21 10:17:41 +00:00
Bernardo Damele
11ecd16099
cosmetics
2011-04-21 10:08:38 +00:00
Miroslav Stampar
9ccf720c05
removing funny remark
2011-04-21 10:06:13 +00:00
Bernardo Damele
a91e6a8440
layout
2011-04-21 10:03:18 +00:00
Miroslav Stampar
cbfe743bad
added a comment
2011-04-21 10:01:58 +00:00
Miroslav Stampar
c84c4d835f
minor update
2011-04-21 09:31:35 +00:00
Bernardo Damele
8e2e06a7a3
layout adjustment
2011-04-21 09:25:42 +00:00
Miroslav Stampar
5052013ffa
minor update
2011-04-20 14:48:23 +00:00
Miroslav Stampar
f909ecb369
bug fix for mssqlserver escape
2011-04-20 13:41:01 +00:00
Miroslav Stampar
e4d3190f41
reverting back to NVARCHAR because of error technique
2011-04-20 12:59:23 +00:00
Miroslav Stampar
3607f03a9e
fix of a minor typo
2011-04-20 12:42:35 +00:00
Miroslav Stampar
1286cc0913
now showing trimmed output in for of warning message (UNION and ERROR techniques affected)
2011-04-20 12:41:58 +00:00
Miroslav Stampar
7993f3f12d
way better for storing bulk of data (like BLOB on mysql)
2011-04-20 11:44:52 +00:00
Miroslav Stampar
04653684cd
revert
2011-04-20 10:34:34 +00:00
Miroslav Stampar
4fadcf0615
improvement for UNION/ERROR case
2011-04-20 10:17:42 +00:00
Miroslav Stampar
1c1c20fb64
minor update
2011-04-20 09:34:00 +00:00
Miroslav Stampar
4b6c524d4c
one more minor update regarding last commit
2011-04-20 09:26:03 +00:00
Miroslav Stampar
44926757da
minor update
2011-04-20 09:23:08 +00:00
Miroslav Stampar
52c98afe93
minor fix
2011-04-20 08:38:46 +00:00
Miroslav Stampar
24435a2c20
implemented "break a tie" request by Andres Riancho
2011-04-20 08:35:47 +00:00
Miroslav Stampar
df0331fe9b
some more refactoring
2011-04-19 23:04:10 +00:00
Miroslav Stampar
3b133303bf
refactoring
2011-04-19 22:54:13 +00:00
Miroslav Stampar
de2479b864
dealing with http://bugs.python.org/issue1602
2011-04-19 22:33:03 +00:00
Miroslav Stampar
9a9838f1e6
cleaning a mess with UPX and virus scanners
2011-04-19 21:57:04 +00:00
Miroslav Stampar
44bbef42f8
minor cosmetics
2011-04-19 20:23:08 +00:00
Miroslav Stampar
b7efa255d6
minor update of usage string
2011-04-19 20:14:56 +00:00
Miroslav Stampar
fc90974940
revert of last commit because of the situation in detection phase where payload is made at the starting point (can't change conf.timeSec in that phase)
2011-04-19 14:50:09 +00:00
Miroslav Stampar
7abbd0c029
removing a leftover
2011-04-19 14:29:51 +00:00
Miroslav Stampar
96b5fede5a
automatic increasing of time delay on lagging connections
2011-04-19 14:28:51 +00:00
Miroslav Stampar
13f8c001a7
minor update
2011-04-19 11:13:53 +00:00
Miroslav Stampar
7a06af9a92
added "lagging" critical message
2011-04-19 10:37:20 +00:00
Miroslav Stampar
959204cff9
minor cosmetics
2011-04-19 09:55:35 +00:00
Miroslav Stampar
597f4dc445
adding procs directory for storing SQL procedure declarations
2011-04-19 09:54:34 +00:00
Miroslav Stampar
9b0db33cc5
initial page request can result in unwanted lag (e.g. slow DNS response,...), hence it's response time shouldn't be a part of response time statistical model
2011-04-19 08:55:38 +00:00
Miroslav Stampar
a7c26366b4
doing that auto default value for --time-sec only for --tor
2011-04-19 08:43:29 +00:00
Miroslav Stampar
4d48ac54dc
automatically increasing default --time-sec value when --tor/--proxy used (not touching anything if explicit --time-sec set)
2011-04-19 08:34:21 +00:00
Miroslav Stampar
b79d4f70f3
cleaner solution for the problem solved with last commit
2011-04-18 14:51:48 +00:00
Miroslav Stampar
f5cff067c6
little hack for --time-sec
2011-04-18 14:46:18 +00:00
Miroslav Stampar
6463cad8c5
minor update for SOAP payloads
2011-04-18 14:29:52 +00:00
Miroslav Stampar
c6a0209649
update of THANKS file
2011-04-18 14:01:45 +00:00
Miroslav Stampar
da9ec67869
removing leftover
2011-04-18 13:43:22 +00:00
Miroslav Stampar
354a2ce249
'chardet' heuristic engine added to the project
2011-04-18 13:38:46 +00:00
Miroslav Stampar
b5aef9bcf9
fix for a bug reported by nightman (TypeError: unsupported operand type(s) for +: 'NoneType' and 'str')
2011-04-18 10:16:38 +00:00
Miroslav Stampar
6fab44d635
minor refactoring and improving of used regex
2011-04-17 22:37:00 +00:00
Miroslav Stampar
76d1f09b0a
minor cosmetics
2011-04-17 22:25:25 +00:00
Miroslav Stampar
9aae447553
minor update for matching SOAP messages
2011-04-17 22:21:32 +00:00
Miroslav Stampar
4fa00121e4
that CONSTANT_RATIO was a pure black magic for dynamic pages. now we have better injection detection workflow than before (False, True, False) and it was just a matter of time for removing this one
2011-04-17 21:58:34 +00:00
Miroslav Stampar
a7366bf710
SOAP refactoring
2011-04-17 21:39:00 +00:00
Miroslav Stampar
c7ff5dcbeb
minor update
2011-04-17 08:48:13 +00:00
Miroslav Stampar
ee88ccf0ac
well, this could be important :)
2011-04-17 08:33:46 +00:00
Miroslav Stampar
ad53e3f551
update of doc/THANKS
2011-04-17 07:39:49 +00:00
Miroslav Stampar
29ee760021
improving time based data retrieval mechanism
2011-04-17 07:24:18 +00:00
Miroslav Stampar
5e70eac98c
fix for a "popular" typo 'iso-5889-1' reported by David Guimaraes
2011-04-16 06:44:29 +00:00
Miroslav Stampar
88c76147e1
removed few trailing whitespace lines
2011-04-15 20:52:08 +00:00
Miroslav Stampar
877d5c1e7f
update of few propsets
2011-04-15 20:43:09 +00:00
Bernardo Damele
79d5804519
added propset
2011-04-15 16:28:48 +00:00
Bernardo Damele
48f916d5a4
Fixed a minor bug
2011-04-15 16:25:42 +00:00
Miroslav Stampar
c16b74ce1a
covering __pivotDumpTable for keyboard and connection exceptions too
2011-04-15 14:21:13 +00:00
Miroslav Stampar
3b6f9945ae
minor fix regarding report from nightman@email.de (...from time to time sqlmap lost the connection...)
2011-04-15 14:15:29 +00:00
Miroslav Stampar
c461fdca54
some refactoring
2011-04-15 13:51:06 +00:00
Miroslav Stampar
bf6ea35145
adding new tool safe2bin for decoding safe encoded values
2011-04-15 13:41:50 +00:00
Miroslav Stampar
a883316e22
i was on some heavy drugs (sys.stdout = fpOut)
2011-04-15 12:58:56 +00:00
Miroslav Stampar
0387654166
update of copyright string (until year)
2011-04-15 12:33:18 +00:00
Miroslav Stampar
4d8a49a87c
more standard way to display hex encoded char (\xff instead of \ff) also compatible with python representation
2011-04-15 11:53:20 +00:00
Miroslav Stampar
05a0e1d3b0
fix for a bug reported by m4l1c3 (TypeError: not all arguments converted during string formatting)
2011-04-15 11:34:14 +00:00
Miroslav Stampar
467d1a50b3
removed debug message that could cause confusion
2011-04-15 11:28:01 +00:00
Miroslav Stampar
8c6f7c7d5f
explicit usage of --time-sec will implicitly turn off auto-adjustment of time delay
2011-04-15 08:52:53 +00:00
Miroslav Stampar
aed994192e
disabling safecharencode for --banner
2011-04-15 08:15:21 +00:00
Miroslav Stampar
3efd9e3959
improved htmlunescape (great for localized html escape codes)
2011-04-14 21:36:13 +00:00
Miroslav Stampar
8ddac7fe5a
minor fix and speedup when pivoting empty table
2011-04-14 21:11:20 +00:00
Miroslav Stampar
384ca98ded
don't let sqlmapNoneDataException for one table to break whole dumpAll()
2011-04-14 20:56:12 +00:00
Miroslav Stampar
dbbaefa79d
minor update (pivot value should be safechardecoded)
2011-04-14 20:38:03 +00:00
Miroslav Stampar
ded28442fb
minor fixes and refactoring regarding safecharencoding
2011-04-14 15:54:00 +00:00
Miroslav Stampar
866cdb4cf7
speed of --replicate is now vastly improved
2011-04-14 14:34:12 +00:00
Miroslav Stampar
96da7ba4eb
just in case for Deprecated modules
2011-04-14 14:01:47 +00:00
Miroslav Stampar
eafab03d99
safe decoding values going into --replicate (as we should have a "replicate" and sqlite3 supports all chars)
2011-04-14 13:53:56 +00:00
Miroslav Stampar
30bfefd638
minor fix
2011-04-14 12:58:03 +00:00
Bernardo Damele
5cf38cd0d7
More cookies to ignore
2011-04-14 12:46:14 +00:00
Bernardo Damele
d462937a2e
added a contributor
2011-04-14 12:42:09 +00:00
Miroslav Stampar
8426d48e2e
minor refactoring
2011-04-14 10:14:46 +00:00
Miroslav Stampar
930262f573
minor update related to the last commit
2011-04-14 10:12:07 +00:00
Miroslav Stampar
1c5427baf8
minor fix
2011-04-14 09:54:29 +00:00
Miroslav Stampar
bb99bd2fbe
one more commit related to the issue with displaying of garbled characters
2011-04-14 09:43:36 +00:00
Miroslav Stampar
04986be4b9
update regarding safe character output together with a small fix for newlines
2011-04-14 09:31:45 +00:00
Miroslav Stampar
5dfb55effc
revert of the last commit because of this http://osvdb.org/show/osvdb/26582
2011-04-14 06:46:32 +00:00
Miroslav Stampar
786f305e1a
minor update
2011-04-14 06:43:08 +00:00
Miroslav Stampar
21114d1748
added IGNORE_PARAMETERS to skip testing of state/session web server parameters
2011-04-13 19:01:02 +00:00
Miroslav Stampar
58a93c5b1f
better beep for MacOSX
2011-04-13 18:32:47 +00:00
Miroslav Stampar
bf55b0b77a
more restrictions on crypt(3) hash recognition to prevent false positives
2011-04-13 14:40:23 +00:00
Miroslav Stampar
d06ae9cd47
implemented retrieved items info for partial union too
2011-04-13 14:33:15 +00:00
Miroslav Stampar
f5f2201bbc
minor cosmetics for partial inband retrieval
2011-04-13 11:25:42 +00:00
Miroslav Stampar
c193b896be
just in case update to prevent gibberish "retrieved: " outputs
2011-04-12 23:07:50 +00:00
Miroslav Stampar
f435f37d71
update of THANKS file
2011-04-12 15:54:00 +00:00
Miroslav Stampar
5346ecbb56
fix for a "accept certificate first time for svn"
2011-04-12 14:25:17 +00:00
Miroslav Stampar
a883ce26b5
fix for a bug reported by ToR (AttributeError: 'NoneType' object has no attribute 'redcode')
2011-04-12 13:25:28 +00:00
Bernardo Damele
1c51e11c5c
Minor adjustments to PgSQL fingerprint
2011-04-12 10:35:33 +00:00
Miroslav Stampar
7324d53997
reference ( http://www.enterprisedb.com/docs/en/9.0/pg/release-9-0.html )
2011-04-12 10:30:33 +00:00
Miroslav Stampar
bc4c2f320c
cosmetics
2011-04-12 10:24:09 +00:00
Miroslav Stampar
2f1786e65f
added active fingerprint for pgsql >= 9.0.3 (reference: http://www.postgresql.org/docs/9.0/static/release-9-0.html )
2011-04-12 10:22:54 +00:00
Bernardo Damele
7c61931b96
Added notes on how to compile and get small shared libraries for UDF
2011-04-12 09:53:52 +00:00
Bernardo Damele
b50b4cd961
MySQL Windows 32-bit DLL recompiled (Visual C++ 2005) and stripped (UPX) - this is the smallest we can get
2011-04-11 22:04:41 +00:00
Bernardo Damele
fdbd8bfe37
initial support for PostgreSQL 9.0 - #223
2011-04-11 22:02:00 +00:00
Bernardo Damele
f4745a95ea
Possible fix for bug reported by David
2011-04-11 21:45:25 +00:00
Miroslav Stampar
136e85abf3
little refresh of PHPIDS rules for --check-payload
2011-04-11 15:37:49 +00:00
Miroslav Stampar
0ae74f27e4
avoiding annoying "payload 'None' possibly..." in case where payload is not specified
2011-04-11 15:24:52 +00:00
Miroslav Stampar
941daa1645
just in case to prevent "object of type 'NoneType' has no len()" error reports
2011-04-11 11:59:02 +00:00
Miroslav Stampar
2db2e9b6a2
now GET forms are also prone to "do you want to fill with random values"
2011-04-11 11:38:41 +00:00
Miroslav Stampar
08d14886fd
added new dev version string
2011-04-11 09:44:44 +00:00
Miroslav Stampar
e20848c711
first commit toward v1.0 (it's smarter to start testing for pivot point from shorter column names as they tend to be some kind of identifiers)
2011-04-11 09:40:52 +00:00
Bernardo Damele
30377621b8
slight update
2011-04-11 00:33:42 +00:00