Commit Graph

  • fd5b665f7d Removing arithmetic operations from false positive checking to minimize affect of character filtering ('>' and '=' have to stay because those are minimal requirements) stamparm 2013-06-26 10:55:34 +02:00
  • eb2012c599 Fix escaper Meatballs 2013-06-24 23:50:33 +01:00
  • 4595b2c287 decodeHexValue Meatballs 2013-06-24 23:45:39 +01:00
  • 5b6c01d739 Escaper Meatballs 2013-06-24 23:41:45 +01:00
  • 604694c0e5 Cleanup queries.xml Meatballs 2013-06-24 23:22:52 +01:00
  • 09e1dc814d Fix concat Meatballs 2013-06-24 23:20:34 +01:00
  • ed40a76c9d Fix dummy table Meatballs 2013-06-24 23:18:47 +01:00
  • a393b17513 modify fingerprint value Meatballs 2013-06-24 15:12:37 +01:00
  • 55a37183d4 Cleanup payloads file Meatballs 2013-06-24 15:04:52 +01:00
  • 550693032b Remote whitespace in databases.py Meatballs 2013-06-24 15:03:08 +01:00
  • 9212b05eeb Add call to execute statements Meatballs 2013-06-24 15:01:44 +01:00
  • b886e47b6d Add unimplemented files Meatballs 2013-06-24 14:53:41 +01:00
  • 62000c6406 Remaining files Meatballs 2013-06-24 14:42:58 +01:00
  • 7b6cc3d183 Add hsql settings Meatballs 2013-06-24 14:38:44 +01:00
  • 20a5d9a16e Include HSQL dummy table Meatballs 2013-06-24 14:37:42 +01:00
  • 355d3f86be hsql payloads and queries xml Meatballs 2013-06-24 14:34:54 +01:00
  • d739d5062d hsql plugin folder Meatballs 2013-06-24 14:34:25 +01:00
  • 0355e29b7c Minor fix (NoneType has no attribute split) Miroslav Stampar 2013-06-24 14:49:53 +02:00
  • 95ed6b7203 Minor patch (Issue #470) Miroslav Stampar 2013-06-24 14:37:45 +02:00
  • 4336a8fa7c Fix for overnight (previously removed : from prefix/suffix was important for XMLType payload) Miroslav Stampar 2013-06-24 14:18:42 +02:00
  • fca6772df6 Implementation for an Issue #468 Miroslav Stampar 2013-06-22 00:12:47 +02:00
  • a72096a345 slightly more appropriate definition of output variable Bernardo Damele 2013-06-19 20:25:01 +01:00
  • cae108d9fc careful at merging pull requests with TABs (#466) Bernardo Damele 2013-06-19 19:49:53 +01:00
  • a53823f9b7 Minor refactoring stamparm 2013-06-19 10:59:26 +02:00
  • 690645f6c7 Cosmetic fix stamparm 2013-06-19 10:50:00 +02:00
  • 20b8186fcc Fix for an Issue #467 stamparm 2013-06-19 10:41:58 +02:00
  • a7787e83b8 Minor fix for case-insensitive union duplicates stamparm 2013-06-18 12:52:36 +02:00
  • aff7092736 Merge pull request #466 from Meatballs1/xp_cmdshell_output Miroslav Stampar 2013-06-18 00:47:08 -07:00
  • 9a6f5a95f5 Minor patch for SQLAlchemy/MSSQL stamparm 2013-06-18 09:36:09 +02:00
  • 92dfb0f817 Minor patch Miroslav Stampar 2013-06-16 12:35:20 +02:00
  • c2dce66a46 Fix for an user reported bug (tbl can be None) Miroslav Stampar 2013-06-16 12:35:05 +02:00
  • c5087399c1 Fix exception if init technique not available Meatballs 2013-06-16 10:47:27 +01:00
  • 2c98507f1e Add better error msg Meatballs 2013-06-16 10:27:08 +01:00
  • caa326774c Fallback to blind Meatballs 2013-06-16 10:22:20 +01:00
  • 63d0e9bb12 Adding support for MsSQL >=2012 hash format (based on commit 70107f74f0be5357654f170a3f321e3e55e81881) Miroslav Stampar 2013-06-13 21:50:35 +02:00
  • de87f0dec7 Update index.html Miroslav Stampar 2013-06-13 21:26:37 +03:00
  • 7781df431f Update index.html Miroslav Stampar 2013-06-13 21:25:44 +03:00
  • 540493a69f Fix for empty strings (previously '' was just removed) Miroslav Stampar 2013-06-11 12:56:20 +02:00
  • f185e5cdd5 Fix for an Issue #463 Miroslav Stampar 2013-06-10 22:26:34 +02:00
  • cdb434805a Using alpha character as a boundary in union/error techniques (instead of ':') to support wider range of (output filtering) cases Miroslav Stampar 2013-06-10 22:14:45 +02:00
  • 6f49b96a2d Fix for an Issue #462 Miroslav Stampar 2013-06-10 12:20:58 +02:00
  • 3583f45ee7 Fix for an Issue #461 Miroslav Stampar 2013-06-10 11:44:56 +02:00
  • ad07add549 Fixing MySQL/stacked payloads (also removing stacked conditional-error version as it's syntatically incorrect) Miroslav Stampar 2013-06-05 14:32:06 +02:00
  • 4ed9766eb8 Update index.html Miroslav Stampar 2013-06-05 01:00:19 +03:00
  • 39612b5d87 Fix for an Issue #457 Miroslav Stampar 2013-06-04 23:46:39 +02:00
  • c1592e8508 Code refactoring (moving import ctypes to be used only when needed) Miroslav Stampar 2013-06-04 22:23:44 +02:00
  • 3e0f747fad Minor fix Miroslav Stampar 2013-06-04 00:05:25 +02:00
  • 213d0ecfb9 Minor fix Miroslav Stampar 2013-06-03 23:32:57 +02:00
  • edc9da1226 Minor refactoring Miroslav Stampar 2013-06-03 15:14:56 +02:00
  • 351c70b390 Locale module screws string.letters, etc. in some cases (e.g. IDLE run) Miroslav Stampar 2013-06-01 14:06:58 +02:00
  • ca53dfad84 Minor fix Miroslav Stampar 2013-06-01 13:44:27 +02:00
  • b7989f93c5 Trivial update regarding last commit Miroslav Stampar 2013-05-30 12:04:56 +02:00
  • ed8f16e754 Minor update on user's request Miroslav Stampar 2013-05-30 12:01:13 +02:00
  • 12870e6ff3 Minor fix Miroslav Stampar 2013-05-30 11:42:27 +02:00
  • 793a8ad349 Minor fix Miroslav Stampar 2013-05-30 11:38:24 +02:00
  • f456b5a28d Bug fix (this payload was also doable on MySQL - with CAST it's strictly being bound to Oracle only) stamparm 2013-05-29 17:41:42 +02:00
  • f4ca4cd6c5 Minor update stamparm 2013-05-29 15:49:09 +02:00
  • c3038fcb65 Minor cosmetic update stamparm 2013-05-29 15:46:59 +02:00
  • 8fbf4b11d2 Trivial update regarding last commit stamparm 2013-05-29 15:45:13 +02:00
  • dfd6ee20bb Patch for an Issue #454 stamparm 2013-05-29 15:26:11 +02:00
  • 60df3e9d1e Minor cosmetic update (displaying 'Technique: DIRECT' instead of 'Technique: None' in case of direct access) stamparm 2013-05-29 15:04:14 +02:00
  • e28b056028 Dummy fix stamparm 2013-05-29 14:26:00 +02:00
  • 840af1fa7b Fix for missing global name __file__ stamparm 2013-05-29 10:20:43 +02:00
  • 6b280d8da4 Putting 2 decimal places for debug messages with performed queries (e.g. to handle a problem with 0 seconds roundup) stamparm 2013-05-28 14:40:45 +02:00
  • b8c5cbc31d Update index.html Miroslav Stampar 2013-05-28 11:51:22 +02:00
  • bc4e1dab19 Getting rid of those ugly warning messages stamparm 2013-05-28 11:24:34 +02:00
  • ba4ed30eed minor update Bernardo Damele A. G. 2013-05-28 10:53:43 +02:00
  • bca058e667 minor fix Bernardo Damele A. G. 2013-05-28 10:49:24 +02:00
  • 949d378bbd minor update to doc Bernardo Damele A. G. 2013-05-28 10:48:09 +02:00
  • 659c0bb418 Minor fix stamparm 2013-05-27 10:38:47 +02:00
  • f3f752d85c Patch for an Issue #452 Miroslav Stampar 2013-05-25 18:52:59 +02:00
  • a85a0e53de Fix for an Issue 'ValueError: Invalid IPv6 URL' Miroslav Stampar 2013-05-25 18:00:04 +02:00
  • e18796dbe1 Minor style update Miroslav Stampar 2013-05-20 22:18:12 +02:00
  • e7ddc2fcab Minor fix Miroslav Stampar 2013-05-23 12:57:33 +04:00
  • eb8e12b7c2 Minor adjustment (for headers like 'name:http://asdas') Miroslav Stampar 2013-05-23 11:29:43 +04:00
  • 19b87074c6 Minor fix Miroslav Stampar 2013-05-22 23:30:33 +04:00
  • 1b3f1a4016 More appropriate naming (also, preventing ambiguities with --smart) stamparm 2013-05-22 23:21:43 +04:00
  • 4b2cf07262 Minor style update stamparm 2013-05-20 16:15:35 +02:00
  • 1a4ea186ca Consistency fix Miroslav Stampar 2013-05-19 23:00:40 +02:00
  • d3ad408a21 Minor cosmetics Miroslav Stampar 2013-05-19 22:17:53 +02:00
  • 4f49dad2ba Minor cosmetics Miroslav Stampar 2013-05-19 01:19:54 +02:00
  • 6cfcc1af63 Minor cosmetic Miroslav Stampar 2013-05-19 01:17:22 +02:00
  • ea5c742595 Update (lagging checking is now always done once when time based compare is done; not only in case if statistical model is being filled) Miroslav Stampar 2013-05-18 21:30:21 +02:00
  • 980a0e3adb Trivial update Miroslav Stampar 2013-05-18 21:00:53 +02:00
  • 1ff98c2ff9 Another minor text update Miroslav Stampar 2013-05-18 21:00:11 +02:00
  • 967513e1bb Minor message update Miroslav Stampar 2013-05-18 20:59:23 +02:00
  • caa4ee96cd Minor cosmetic update Miroslav Stampar 2013-05-18 18:28:44 +02:00
  • 6608410320 Adding a question after WAF has been identified Miroslav Stampar 2013-05-18 18:26:40 +02:00
  • b2b3b3b5a6 Minor bug fix (level names not properly used in non-logger output) Miroslav Stampar 2013-05-18 16:44:21 +02:00
  • f24c8c6b6b Changing logging type to warning for parsed error messages Miroslav Stampar 2013-05-18 16:17:56 +02:00
  • dcea745576 Minor update (not displaying safe enclosings in table dumps) Miroslav Stampar 2013-05-18 16:13:34 +02:00
  • e528ea8208 Minor language fix Miroslav Stampar 2013-05-18 16:02:34 +02:00
  • 03732d2592 Minor fix stamparm 2013-05-17 16:04:05 +02:00
  • b26ecfe087 Patch for an Issue #449 stamparm 2013-05-17 15:14:51 +02:00
  • 76b4e1ccb9 Implementation for an Issue #450 stamparm 2013-05-17 15:04:25 +02:00
  • 7ba9e75c97 Minor update related to the last commit stamparm 2013-05-16 15:23:20 +02:00
  • 7ea8dd9428 MySQL is specific (types are automatically being converted without any warning/error) stamparm 2013-05-16 15:12:36 +02:00
  • f1f34a65a2 Minor update stamparm 2013-05-15 13:38:26 +02:00
  • 41f0e91662 Minor update (related to last commit) stamparm 2013-05-13 14:50:03 +02:00
  • cb9ea67c8d Code refactoring (moving progress.py to lib/utils) stamparm 2013-05-13 14:48:39 +02:00