Commit Graph

  • fed0212631 now working with recursive queries too Miroslav Stampar 2012-05-27 10:03:02 +00:00
  • 71ff081fde minor update Miroslav Stampar 2012-05-27 09:11:19 +00:00
  • 09f2144485 full page read is not needed in DNS exfiltration mode Miroslav Stampar 2012-05-26 21:28:43 +00:00
  • 4e6fcce9ca minor update Miroslav Stampar 2012-05-26 07:04:32 +00:00
  • ce077137c9 minor language update Miroslav Stampar 2012-05-26 07:01:37 +00:00
  • d335ec0c34 turning back on time auto-adjustment mechanism (if turned off) after a threshold run of valid chars Miroslav Stampar 2012-05-26 07:00:26 +00:00
  • 00d22f013f some consistency in variable naming at the file level Miroslav Stampar 2012-05-25 10:08:55 +00:00
  • db526bdbc0 minor update (tainted values are not checked any more in multipleTargets mode) Miroslav Stampar 2012-05-25 09:52:17 +00:00
  • dc20bff1d0 minor update Miroslav Stampar 2012-05-25 08:30:24 +00:00
  • c394610740 adding switch --skip-urlencode to skip URL encoding of POST data Miroslav Stampar 2012-05-24 23:30:33 +00:00
  • 7657bbeaf9 minor update Miroslav Stampar 2012-05-24 22:32:06 +00:00
  • 86fdad2bfa minor update Miroslav Stampar 2012-05-24 22:07:50 +00:00
  • eed8d7eb5d finalizing support for IPv6 Miroslav Stampar 2012-05-24 21:55:57 +00:00
  • b6d37d766a minor update regarding IPv6 support Miroslav Stampar 2012-05-24 21:49:20 +00:00
  • 92286104e3 minor just in case update Miroslav Stampar 2012-05-24 21:39:10 +00:00
  • 3e9c57d177 minor fix Miroslav Stampar 2012-05-24 21:36:35 +00:00
  • be76928293 minor fix Miroslav Stampar 2012-05-24 20:53:01 +00:00
  • 3f6bc1f3c2 minor fix Miroslav Stampar 2012-05-24 18:05:33 +00:00
  • 1e18168cc8 fix for one silent bug and small language update Miroslav Stampar 2012-05-23 16:35:40 +00:00
  • 2538e2d5b4 fixing an issue with --file-read and ROW() MySQL payload (it's internal caching mechanism prevents error message if FROM part is not unique enough dumping only partial file content); minor refactoring Miroslav Stampar 2012-05-22 09:33:22 +00:00
  • 2c057d5b3d minor style update Miroslav Stampar 2012-05-21 22:40:52 +00:00
  • 3a9e266d78 adding revisited wildcard LIKE payloads Miroslav Stampar 2012-05-21 21:49:54 +00:00
  • 602369c762 reverting last changes on boundaries Miroslav Stampar 2012-05-21 09:20:46 +00:00
  • 588d829be6 update of doc/THANKS Miroslav Stampar 2012-05-21 08:34:12 +00:00
  • 1500b3fccd adding a new payload boundaries by smcintyre@securestate.com Miroslav Stampar 2012-05-21 08:31:37 +00:00
  • 0e8d8577a7 adding a DB2 patch from smcintyre@securestate.com Miroslav Stampar 2012-05-21 08:26:19 +00:00
  • 079e0e1434 minor bug fix Miroslav Stampar 2012-05-18 08:51:50 +00:00
  • bbfa4b6d5d minor update Miroslav Stampar 2012-05-14 14:38:16 +00:00
  • 333f8057a5 minor fix (when redirected path has non-ASCII char and conf.url is unicode) and bits along with pieces Miroslav Stampar 2012-05-14 14:06:43 +00:00
  • 595f69fa2c minor language update Miroslav Stampar 2012-05-10 18:30:25 +00:00
  • 35f400b45b minor language upgrade Miroslav Stampar 2012-05-10 18:25:12 +00:00
  • 80aedbe284 adding a warning about --tor switch Miroslav Stampar 2012-05-10 18:17:32 +00:00
  • b81fe42d4b turning off null connection on -o when --tor used (not compatible) Miroslav Stampar 2012-05-10 17:50:54 +00:00
  • efdd86ddcc minor just in case patch Miroslav Stampar 2012-05-10 14:22:34 +00:00
  • 6367f59b98 minor code refactoring Miroslav Stampar 2012-05-10 14:15:17 +00:00
  • 12d32f58f2 fix for that SOAP reported bug Miroslav Stampar 2012-05-10 13:39:54 +00:00
  • 1418ae9767 little refactoring of parseUnionPage together with a patch for some special case Miroslav Stampar 2012-05-09 18:47:40 +00:00
  • 7fb1f3fc70 minor renaming Miroslav Stampar 2012-05-09 18:26:02 +00:00
  • 11d9859199 making nice code Miroslav Stampar 2012-05-09 18:25:04 +00:00
  • b0a8238774 minor fixes Miroslav Stampar 2012-05-09 14:58:16 +00:00
  • 9fa3619262 minor fix Miroslav Stampar 2012-05-09 14:00:07 +00:00
  • 56a3431be6 minor update for empty tables (skipping other techniques) Miroslav Stampar 2012-05-09 10:34:21 +00:00
  • 6177317a17 minor update Miroslav Stampar 2012-05-09 10:06:23 +00:00
  • 37f2709197 making a generic solution for all "Generic comment"/MsAccess cases (it's the only DBMS which doesn't accept --, hence replacing generic comment with %00 for it) Miroslav Stampar 2012-05-09 09:08:23 +00:00
  • fdf61015ad minor patch Miroslav Stampar 2012-05-09 08:41:05 +00:00
  • e419177871 minor update Miroslav Stampar 2012-05-08 17:28:19 +00:00
  • deec97dfe3 adding Frontbase to error message regexes Miroslav Stampar 2012-05-08 17:02:58 +00:00
  • eccd4da00f minor fix Miroslav Stampar 2012-05-08 15:03:33 +00:00
  • 938d9ff23e doing all the work for the users so they wouldn't strain their little hands Miroslav Stampar 2012-05-08 15:00:23 +00:00
  • 524dd75ff2 that query variable hasn't been used anywhere (obsolete for some time) Miroslav Stampar 2012-05-08 14:34:40 +00:00
  • 6af110d631 avoiding --no-cast/--hex warning message before a DBMS is fingerprinted Miroslav Stampar 2012-05-08 14:06:41 +00:00
  • 64c241fe92 limiting original UNION query results to only 1 result (potentially speeding things up in some cases) Miroslav Stampar 2012-05-08 13:45:53 +00:00
  • e00f4a8934 minor cosmetics Miroslav Stampar 2012-05-08 10:50:04 +00:00
  • a121339395 automatically writing uncracked hashes to a file for eventual further processing Miroslav Stampar 2012-05-08 10:46:05 +00:00
  • 80ee687b41 minor beauty patch Miroslav Stampar 2012-05-07 13:51:31 +00:00
  • e9f6b00e26 minor fix in a KeepAlive library Miroslav Stampar 2012-05-07 13:36:36 +00:00
  • 57234e1ff5 fix for proper (international character) inference on MsAccess Miroslav Stampar 2012-05-03 23:13:48 +00:00
  • 96299d3d5d minor refactoring Miroslav Stampar 2012-05-03 22:34:18 +00:00
  • cc28f6db6b minor update Miroslav Stampar 2012-05-01 20:43:16 +00:00
  • 8013a64f8c minor refactoring Miroslav Stampar 2012-05-01 19:57:30 +00:00
  • c71d435d9f making "id"-like columns prioritized for ORDER BY in MySQL Miroslav Stampar 2012-05-01 19:52:02 +00:00
  • 17efeaae7f causing too much confusion among dummy users Miroslav Stampar 2012-05-01 09:04:11 +00:00
  • 458a73c9b4 few consistency fixes Miroslav Stampar 2012-04-29 23:09:00 +00:00
  • 694b14111f skipping suffix if comment is used in agent.suffixQuery (and --suffix not explicitly set) Miroslav Stampar 2012-04-27 13:16:51 +00:00
  • c7a606637f switching few readInput defaults for brute forcing when no table/column found Miroslav Stampar 2012-04-27 12:59:22 +00:00
  • 1e45ee9ab6 reverting back to smaller UNION ranges as that mechanism for automatic extending was implemented few days ago Miroslav Stampar 2012-04-25 20:37:39 +00:00
  • 6f67dc85ee adding --invalid-bignum (Havij like bignum style for invalidating/negating values); renaming --logical-negate to --invalid-logical Miroslav Stampar 2012-04-25 20:29:07 +00:00
  • 4da03d898e Added support to create files with a visual basic script - no longer reliant on debug.exe so works on Windows 64-bit too. Fixes #236 Bernardo Damele 2012-04-25 07:40:42 +00:00
  • 6116853025 Minor layout adjustments Bernardo Damele 2012-04-24 17:01:24 +00:00
  • cec432f94d minor update Miroslav Stampar 2012-04-23 14:43:59 +00:00
  • 697768c01a adding --purge-output to be one of mandatory switches Miroslav Stampar 2012-04-23 14:42:24 +00:00
  • d57d5e4b2c minor update Miroslav Stampar 2012-04-23 14:33:36 +00:00
  • 1eecfb3dce adding new file related to the last commit Miroslav Stampar 2012-04-23 14:25:16 +00:00
  • 095b25e1d1 adding option '--purge' Miroslav Stampar 2012-04-23 14:24:23 +00:00
  • 3532d23933 automatically extending ranges for UNION tests in case where at least one other injection technique is usable (boundaries has been established) Miroslav Stampar 2012-04-23 13:41:36 +00:00
  • eb73cab636 increased UNION test ranges Bernardo Damele 2012-04-23 11:54:52 +00:00
  • be2da77bf8 minor update Miroslav Stampar 2012-04-23 10:15:04 +00:00
  • 21c6b52198 minor fix Miroslav Stampar 2012-04-23 10:11:00 +00:00
  • 775134639d minor update Miroslav Stampar 2012-04-20 20:33:15 +00:00
  • 072e08836f Falling back to unionReadFile() when --file-read does not work against MySQL. This happens when the session user does not have INSERT privilege, required to run LOAD DATA INFILE Bernardo Damele 2012-04-19 14:05:45 +00:00
  • 2b1b4c0742 minor fix Miroslav Stampar 2012-04-18 10:01:04 +00:00
  • 6ebb621228 adding support for (custom) POST injection (marking injection point with '*' in conf.data) Miroslav Stampar 2012-04-17 14:23:00 +00:00
  • efd27d7ade minor renaming Miroslav Stampar 2012-04-17 08:41:19 +00:00
  • ccd6fb70a8 minor refactoring Miroslav Stampar 2012-04-15 17:17:30 +00:00
  • 965c1511a6 adding new tamper script Miroslav Stampar 2012-04-15 17:10:43 +00:00
  • 601d118c68 reverting back to UNION ALL scheme (UNION is doing another DISTINCT on data causing problems on some column types) Miroslav Stampar 2012-04-15 16:59:03 +00:00
  • 71b0acc16f minor fix (checking for full inband should be done with ORIGINAL - more concise) Miroslav Stampar 2012-04-15 16:43:18 +00:00
  • 5772c52f46 minor refactoring/fix (randQuery is just a part (e.g. abc) of phrase (def:abc:ghi) - phrase should be searched for, not just randQuery); both phrases should be inside the content for it to be full-inband injectable (...UNION ALL SELECT phrase UNION ALL SELECT phrase2....) Miroslav Stampar 2012-04-15 16:33:47 +00:00
  • ae8c70e895 another cosmetics Miroslav Stampar 2012-04-13 15:11:44 +00:00
  • d765cdc3a3 minor cosmetics Miroslav Stampar 2012-04-13 15:10:40 +00:00
  • 54576ab3a6 making a random choice from candidates Miroslav Stampar 2012-04-13 10:54:30 +00:00
  • bbbcc95fe5 use it only if page is stable Miroslav Stampar 2012-04-13 10:19:26 +00:00
  • 414c74b8aa new payload Miroslav Stampar 2012-04-13 08:16:33 +00:00
  • 052d9455fe warning user in cases of "User xyz already has more than 'max_user_connections' active connections" Miroslav Stampar 2012-04-12 09:44:54 +00:00
  • 831f79b851 minor generalization Miroslav Stampar 2012-04-12 09:30:19 +00:00
  • c7422546e1 tiny update Miroslav Stampar 2012-04-11 23:01:38 +00:00
  • 2bad73a981 minor update Miroslav Stampar 2012-04-11 21:48:44 +00:00
  • e195de2093 correcting comment on reflective removal function Miroslav Stampar 2012-04-11 21:41:48 +00:00
  • b45ae10da4 minor fixes Miroslav Stampar 2012-04-11 21:36:37 +00:00
  • 627bfc589f some more updates in reflective removal mechanism Miroslav Stampar 2012-04-11 21:26:00 +00:00