Commit Graph

  • ca3e12ae73 added calculateDeltaSeconds method for dealing with non-deterministic time behaviour in some cases (e.g. WAITFOR DELAY in case of MSSQL) Miroslav Stampar 2010-05-13 11:05:35 +00:00
  • 762781e94d Minor bug fix, %TEMP% is expanded only in xp_cmdshell (MSSQL), so disabled for MySQL/PGSQL Bernardo Damele 2010-05-13 10:40:15 +00:00
  • 091e0b2e05 Layout adjustment Bernardo Damele 2010-05-13 09:51:15 +00:00
  • 0a4c1f8aec unfix (conf.timeSec is an integer - my fault) Miroslav Stampar 2010-05-13 09:34:08 +00:00
  • 2323d858a9 modification of temporary directory from C:/Windows/Temp to %TEMP% Miroslav Stampar 2010-05-13 09:32:27 +00:00
  • 2fdac83607 minor fix Miroslav Stampar 2010-05-13 08:27:51 +00:00
  • 9efe001515 SQLite does not support BETWEEN Bernardo Damele 2010-05-12 22:02:47 +00:00
  • b2c5807109 Updated Bernardo Damele 2010-05-12 22:02:18 +00:00
  • 893bc04fe4 changes regarding Feature #157 (Evaluate BETWEEN for inference algorithm) Miroslav Stampar 2010-05-12 11:30:32 +00:00
  • 8b74c405f5 Minor output bug fix Bernardo Damele 2010-05-11 14:15:03 +00:00
  • 457d32c73e Proper displaying of debug messages (-v >= 2) Bernardo Damele 2010-05-11 13:58:53 +00:00
  • 1a8beebc8c minor fix Miroslav Stampar 2010-05-11 13:55:30 +00:00
  • 1e5ecbaa97 speedup of initial session file handling Miroslav Stampar 2010-05-11 13:36:30 +00:00
  • 6752e66164 added charsetType=2 (integer) to queryOutputLength Miroslav Stampar 2010-05-11 12:23:38 +00:00
  • 430a25407b fixed that thread partial output problem (one character behind) reported by Kasper Fons Miroslav Stampar 2010-05-11 11:06:21 +00:00
  • 74860fee2a Updated Bernardo Damele 2010-05-10 14:52:02 +00:00
  • 4c91b5a896 Minor fix Bernardo Damele 2010-05-10 14:18:41 +00:00
  • 65a05452f7 Added option --search to work in conjunction with -D (done), -T (soon) or -C (replaces --dump -C) - See #190: * --search -D foobar: searches all database names like the ones provided * --search -T foobar: searches all databases' table names like the ones provided (soon) * --search -C foobar: replaces --dump -C Bernardo Damele 2010-05-07 13:40:57 +00:00
  • 7b6050f3c1 Minor update Bernardo Damele 2010-05-06 14:18:25 +00:00
  • 8dbf89afe4 Minor update Bernardo Damele 2010-05-06 11:22:53 +00:00
  • 783c48f6e9 Merged history into user's manual Bernardo Damele 2010-05-06 11:09:03 +00:00
  • 44ea8f1861 Minor adjustment Bernardo Damele 2010-05-06 11:00:58 +00:00
  • 7bf31f54b8 Updated history SGML file Bernardo Damele 2010-05-06 10:54:13 +00:00
  • 147e14356d Major bug fix (reported by Thierry Zoller) Bernardo Damele 2010-05-06 10:52:40 +00:00
  • 4928c684b3 one more thing Miroslav Stampar 2010-05-04 08:45:10 +00:00
  • 789dd6c66f more quick fixes Miroslav Stampar 2010-05-04 08:43:14 +00:00
  • af701cdaa2 better way to handle that last commit problem Miroslav Stampar 2010-05-04 08:36:35 +00:00
  • 5bc07426e0 added exception handler around block reported by Thierry Zoller Miroslav Stampar 2010-05-04 08:03:48 +00:00
  • 107a900f51 Updated Bernardo Damele 2010-05-03 12:57:17 +00:00
  • 90d9900371 Minor bug fix to consider --start and --stop also in partial UNION query SQL injection Bernardo Damele 2010-04-30 15:48:40 +00:00
  • 4d46f997a7 Minor bug fix Bernardo Damele 2010-04-29 13:34:03 +00:00
  • d8e5585c66 fixed a bug reported by Mosk Dmitri (infoMsg UnboundLocalError) Miroslav Stampar 2010-04-29 08:30:29 +00:00
  • a588b2020b Added history SGML file Bernardo Damele 2010-04-26 15:00:53 +00:00
  • d003283939 fix - php backdoor script was not running on xampp Miroslav Stampar 2010-04-26 13:01:16 +00:00
  • 2665066dae Updated changelog file Bernardo Damele 2010-04-26 12:35:39 +00:00
  • fa48d26f95 Minor cosmetic fix Bernardo Damele 2010-04-26 12:34:21 +00:00
  • 7eef76f1b0 added basic option validation for start/stop values regarding David Guimaraes mail Miroslav Stampar 2010-04-26 11:23:12 +00:00
  • a1b1f960cc Finally fixed and adapted all code around to the new isWindowsDriveLetterPath() function Bernardo Damele 2010-04-23 16:34:20 +00:00
  • 0f80768e66 Reverted Bernardo Damele 2010-04-22 16:35:22 +00:00
  • 7b070acd17 Reimported needed imports! Bernardo Damele 2010-04-22 16:13:22 +00:00
  • 3087c27659 Updated doc Bernardo Damele 2010-04-22 10:37:58 +00:00
  • 1bcec80e95 fix for that takeover bug Ethan Robish posted (Windows/PHP) Miroslav Stampar 2010-04-22 10:31:33 +00:00
  • 7d3a200ab8 fix for Bug #183 Miroslav Stampar 2010-04-19 15:25:52 +00:00
  • 2840f20605 Minor bug fix Bernardo Damele 2010-04-17 15:43:08 +00:00
  • 915d3441e9 some code refactoring Miroslav Stampar 2010-04-16 19:57:00 +00:00
  • 1bdf94f236 fix for Bug #164 (Proper usage of special characters in paths) Miroslav Stampar 2010-04-16 15:46:31 +00:00
  • bece99908c fix regarding Bug #164 (Proper usage of special characters in paths) - not clear if that's all Miroslav Stampar 2010-04-16 15:12:42 +00:00
  • 938a3ab0b9 fix for Bug #183 (--threads dot output) Miroslav Stampar 2010-04-16 13:40:02 +00:00
  • 1aeaa5db47 implementation of Feature #176 (Safe URL: avoid being kicked out after N unsuccessful requests) Miroslav Stampar 2010-04-16 12:44:47 +00:00
  • e11d511cad Updated doc Bernardo Damele 2010-04-15 12:12:53 +00:00
  • d034bf29ce Add new "hinted" feature to MSSQL's getTables() Bernardo Damele 2010-04-15 12:09:26 +00:00
  • 14f8514fb5 Minor "revert" to make resume of queries work again Bernardo Damele 2010-04-15 11:56:47 +00:00
  • a0c8adc266 Minor bug fix to add the "hinted" request to the total number of requests performed Minor layout adjustments. Bernardo Damele 2010-04-15 10:08:27 +00:00
  • 5e86087cb1 Minor bug fix for -d to avoid resuming queries when they're SELECT on sqlmap own tables, aligned to same resume of -u now. Bernardo Damele 2010-04-15 10:06:38 +00:00
  • 17554759b7 implemented feature request from Ole Rasmussen regarding table name retrieval speedup Miroslav Stampar 2010-04-15 09:36:13 +00:00
  • 1ab78ce60e Added support to directly connect also to SQLite 2 db file Bernardo Damele 2010-04-13 22:43:38 +00:00
  • fee062781f Minor adjustment Bernardo Damele 2010-04-13 11:13:01 +00:00
  • da1ea48947 added some nagging for connection details Miroslav Stampar 2010-04-13 11:00:15 +00:00
  • 4f299f22bf removed timeout keyword which is not supported on linux build Miroslav Stampar 2010-04-13 10:11:14 +00:00
  • 6762f592c1 direct connection supported only on Windows machines Miroslav Stampar 2010-04-13 08:57:47 +00:00
  • 939fa5d2c4 some fixes Miroslav Stampar 2010-04-13 08:29:15 +00:00
  • 9e29120603 Minor fix to make MS Access direct access to work also from Linux Bernardo Damele 2010-04-12 15:52:40 +00:00
  • eecee3b274 Added resume functionality to -d and fixed logging with -d Bernardo Damele 2010-04-12 09:35:20 +00:00
  • e0d0913fc6 Updated doc Bernardo Damele 2010-04-12 09:34:20 +00:00
  • b72ddb6f1e Fixes non-deterministic unsorted results for most of the DBMSes - see #185 Bernardo Damele 2010-04-09 15:48:53 +00:00
  • 822d22299f Updated Bernardo Damele 2010-04-09 13:48:02 +00:00
  • fcceceed45 fix for bug reported by shiftzwei@gmail.com regarding formatDBMSfp with unknown DBMS version Miroslav Stampar 2010-04-09 10:40:08 +00:00
  • 63c70018ca fix for that update (conf.cj) problem mentioned by shiftzwei@gmail.com Miroslav Stampar 2010-04-09 10:16:15 +00:00
  • effc7dc41c Minor adjustment to notify the user that the --auth-cred format for NTLM authentication is "DOMAIN\user:password" Bernardo Damele 2010-04-07 09:47:14 +00:00
  • 652daa616e Minor bug fix and layout adjustments Bernardo Damele 2010-04-06 21:57:15 +00:00
  • 758a858785 Minor adjustments Bernardo Damele 2010-04-06 20:40:14 +00:00
  • 5556db80db fix for that sqlite thread nagging with undocumented argument check_same_thread Miroslav Stampar 2010-04-06 16:01:37 +00:00
  • 6e7be5edb0 another fix Miroslav Stampar 2010-04-06 15:51:36 +00:00
  • 3fe9f9cac9 another fix Miroslav Stampar 2010-04-06 15:28:34 +00:00
  • a6a2e993cc minor update Miroslav Stampar 2010-04-06 15:24:56 +00:00
  • c303feab17 fix Miroslav Stampar 2010-04-06 15:14:32 +00:00
  • e2810003ae more update Miroslav Stampar 2010-04-06 15:12:52 +00:00
  • c24f1cc07c some update Miroslav Stampar 2010-04-06 14:59:31 +00:00
  • 60f04f0a41 new module for interruptable threads Miroslav Stampar 2010-04-06 14:33:57 +00:00
  • bd669dd6fa Updated Bernardo Damele 2010-04-06 10:32:56 +00:00
  • 2d55ec19a3 Minor code restyling Bernardo Damele 2010-04-06 10:15:19 +00:00
  • e29e8f82f9 fix for "Problem with --dbms set" reported by David Guimaraes Miroslav Stampar 2010-04-05 23:09:35 +00:00
  • 0a363d3f2b fix for not properly clearing cookies when in multiple targets scanning mode spotted by Kasper Fons Miroslav Stampar 2010-04-04 14:38:48 +00:00
  • 4129cb22a7 update regarding bug reported by Ole Rasmussen Miroslav Stampar 2010-04-03 19:41:47 +00:00
  • cad8f61d55 Force pymssql to version >= 1.0.2 Bernardo Damele 2010-03-31 15:31:11 +00:00
  • b19de015c5 Minor bugs fixes Bernardo Damele 2010-03-31 13:52:51 +00:00
  • 5fdebb5d5b Added support to directly connect also to Microsoft SQL Server database. Fixed direct connection to always use the same query as of UNION query SQL injection (= one query with multiple columns/entries output). Minor fixes to Firebird/Access/SQLite connectors to use connector's execute()/fetchall() as wrapper for third-party libraries' methods. Forced conf.timeout to 10 seconds when directly connecting to database. Slightly improved regular expression to parse -d parameter. Added import check for all connectors' third-party libraries. Code refactoring: * Moved conf.direct request to direct() function in lib/request/direct.py (code reused where needed). * Back-delegated to generic connector close() and other methods. Bernardo Damele 2010-03-31 10:50:47 +00:00
  • d583cc07e7 ms access update Miroslav Stampar 2010-03-30 15:04:55 +00:00
  • 1973024ebf added support for reusing connections Miroslav Stampar 2010-03-30 13:52:47 +00:00
  • f0729565a9 fixes for sqlite Miroslav Stampar 2010-03-30 13:36:23 +00:00
  • 8702cce760 fix Miroslav Stampar 2010-03-30 13:23:20 +00:00
  • c2a6f21095 refactoring regarding usage of conf.dbmsConnector.connect() Miroslav Stampar 2010-03-30 13:03:19 +00:00
  • 88d74a00c1 ms access connector update Miroslav Stampar 2010-03-30 12:48:51 +00:00
  • a02ec29c15 too Miroslav Stampar 2010-03-30 11:52:45 +00:00
  • c9c9c1fb2f replace only first occurrence Miroslav Stampar 2010-03-30 11:52:01 +00:00
  • bfc12e93c5 ms access returns -1 for True Miroslav Stampar 2010-03-30 11:33:51 +00:00
  • ae3455a0c2 more update Miroslav Stampar 2010-03-30 11:28:14 +00:00
  • 738c210075 update Miroslav Stampar 2010-03-30 11:21:26 +00:00
  • 87d8c6719e updates, fixes and stuff Miroslav Stampar 2010-03-30 11:06:30 +00:00
  • f04449be03 update Miroslav Stampar 2010-03-29 23:48:21 +00:00