Commit Graph

  • 7d313ac911 few more fixes for proper redirecting mechanism Miroslav Stampar 2012-03-15 19:47:59 +00:00
  • 48e8c978fb Minor fix, way more to do for --search -C for MSSQL Bernardo Damele 2012-03-15 17:55:49 +00:00
  • 86c4650058 Minor bug fix - revert Bernardo Damele 2012-03-15 17:12:24 +00:00
  • cc15373769 More explicit function name also getRatioValue parameter has nothing to do with comparison at this stage as far as I can see (that might have fixed another "bug", to be checked later) Bernardo Damele 2012-03-15 16:29:28 +00:00
  • 4520744b4d second step toward negative logic support (ported to detection phase too) - works well with --string, --regexp and --code now Bernardo Damele 2012-03-15 16:25:26 +00:00
  • 0013b0970f Minor layout adjustments - foundDb is misleading at that stage Bernardo Damele 2012-03-15 16:07:16 +00:00
  • ddd92476a8 minor fix Miroslav Stampar 2012-03-15 15:58:25 +00:00
  • 19beb912fa first step toward negative logic support Miroslav Stampar 2012-03-15 15:52:12 +00:00
  • 8dd570057b minor fix (double traffic log for -t in case of HTTP error) Miroslav Stampar 2012-03-15 14:51:16 +00:00
  • f7df755f37 minor update Miroslav Stampar 2012-03-15 12:55:22 +00:00
  • 3d39c6cb3b some fixes here and there Miroslav Stampar 2012-03-15 12:14:50 +00:00
  • 3d9b1599d1 minor update Miroslav Stampar 2012-03-15 11:45:32 +00:00
  • 91f1d6141f minor fix Miroslav Stampar 2012-03-15 11:24:55 +00:00
  • a8c9a47092 redirect logic rewritten from scratch Miroslav Stampar 2012-03-15 11:10:58 +00:00
  • 84479eebe9 minor fix Miroslav Stampar 2012-03-15 08:55:42 +00:00
  • 890bf708bc Minor fixes to make --os-* switch work again against MySQL/Windows/ASP.NET (where stacked queries are supported) Bernardo Damele 2012-03-15 00:19:57 +00:00
  • 8cf5d260fd Application Data is not a temporary directory writable by everybody Miroslav Stampar 2012-03-14 23:44:29 +00:00
  • 1e71b24dca More info messages to prove xp_cmdshell (and temporary directory choosen) worked Bernardo Damele 2012-03-14 22:41:53 +00:00
  • c735d846ee The default temporary directory as to stay as is, do not touch this code snippet anymore please Bernardo Damele 2012-03-14 22:39:46 +00:00
  • 52a8b25ff4 minor fix Miroslav Stampar 2012-03-14 14:31:41 +00:00
  • ca0d068575 distinguishing NULL from BLANK Miroslav Stampar 2012-03-14 13:52:23 +00:00
  • e38b59a2ae minor update Miroslav Stampar 2012-03-14 13:16:49 +00:00
  • cee9ff7885 proper parsing of content in partial union technique Miroslav Stampar 2012-03-14 11:23:30 +00:00
  • 61ad3b999a fix for a crash with partial union and --hex Miroslav Stampar 2012-03-14 10:31:24 +00:00
  • a7fbc55748 grammar fix Miroslav Stampar 2012-03-13 22:03:23 +00:00
  • edfcddd3c3 minor fix for logging only cookies used by request (e.g. --load-cookies case) Miroslav Stampar 2012-03-13 10:58:15 +00:00
  • 34b0935cb3 refactoring "echo 1" quick test for xp_cmdshell console output Miroslav Stampar 2012-03-13 10:36:49 +00:00
  • e827f41cdb using pickle HIGHEST_PROTOCOL just in case Miroslav Stampar 2012-03-13 09:35:37 +00:00
  • e6c610abab minor fix Miroslav Stampar 2012-03-13 09:14:56 +00:00
  • cda8815634 introducing safe deprecation mechanism for HashDB versioning Miroslav Stampar 2012-03-12 22:55:57 +00:00
  • 48bcde478e more general update Miroslav Stampar 2012-03-12 15:29:55 +00:00
  • 1d0c8a7f44 minor update Miroslav Stampar 2012-03-12 15:19:02 +00:00
  • 6ed1b04bbe minor update Miroslav Stampar 2012-03-12 13:27:07 +00:00
  • 48592f2515 minor adjustments Bernardo Damele 2012-03-09 18:34:18 +00:00
  • be9b103b51 minor bug fix Bernardo Damele 2012-03-09 18:02:50 +00:00
  • 012fc21b49 Improvements to column(s) search: now it's possible to search column(s) in provided table(s) across all databases, search column(s) across all tables in provided database(s) or let sqlmap alone identify the databases' tables - this is now implemented for error-based, union query and direct connection. Work is still required for boolean-based and time-based. Adapted the queries.xml file accordingly Bernardo Damele 2012-03-09 17:47:50 +00:00
  • c878dd3e5a doing a dummy test for --os-shell in case of xp_cmdshell Miroslav Stampar 2012-03-09 14:21:41 +00:00
  • 4ac2611a56 Added another tamper script Bernardo Damele 2012-03-09 12:09:19 +00:00
  • d9e499af9f Set Id property Bernardo Damele 2012-03-09 12:05:21 +00:00
  • a0b46963cb minor fix for some special "unusable" cases (seen on Access/ODBC/Linux setup) Miroslav Stampar 2012-03-09 10:28:19 +00:00
  • 7330dff255 Minor bug fix for --search -C so that now if not columns are found (with criteria specified, e.g. -D testdb -T testtable), it won't ask to dump for the entries Bernardo Damele 2012-03-08 16:57:53 +00:00
  • e678219a8c minor update Miroslav Stampar 2012-03-08 15:51:30 +00:00
  • ae87df5670 leftover Bernardo Damele 2012-03-08 15:45:33 +00:00
  • 5a83f1c5f7 minor update Miroslav Stampar 2012-03-08 15:43:22 +00:00
  • 4bc6f3f6c9 Minor bug fix so that --search -T tablename -D db1,db2 now correctly forges the query concatenating db1 and db2 with a OR, not an AND anymore Bernardo Damele 2012-03-08 15:32:05 +00:00
  • 68b9d48d0a minor update Miroslav Stampar 2012-03-08 15:30:23 +00:00
  • 2ab80bfb2c minor bug fix Miroslav Stampar 2012-03-08 15:24:05 +00:00
  • c79807f5fb Minor layout adjustments Bernardo Damele 2012-03-08 15:11:24 +00:00
  • 775e424bf2 bug fix for using --no-cast and --hex switches together Miroslav Stampar 2012-03-08 15:04:52 +00:00
  • 11c7cc5224 minor temporary fix Miroslav Stampar 2012-03-08 11:08:43 +00:00
  • 98a3e43f53 bug fix for writing raw pickled data into SQLite HashDB Miroslav Stampar 2012-03-08 10:57:47 +00:00
  • cd28eb6544 minor update regarding --load-cookies Miroslav Stampar 2012-03-08 10:19:34 +00:00
  • 2c87d061e9 minor update Miroslav Stampar 2012-03-08 10:03:59 +00:00
  • 9ca8bc4d51 minor bug fix Miroslav Stampar 2012-03-08 09:52:33 +00:00
  • b4cf8b05b3 added switch --load-cookies Miroslav Stampar 2012-03-07 14:48:45 +00:00
  • 4cfea96471 minor update Miroslav Stampar 2012-03-05 09:56:48 +00:00
  • 0ead1fd87e minor update Miroslav Stampar 2012-03-05 09:42:52 +00:00
  • ac5a752b12 Oracle's XMLType doesn't like '#' char too Miroslav Stampar 2012-03-01 11:59:37 +00:00
  • 761ec7529a minor appereance fix Miroslav Stampar 2012-03-01 11:52:30 +00:00
  • f4e410db16 minor fix Miroslav Stampar 2012-03-01 10:17:39 +00:00
  • 1ec56f93ec minor update Miroslav Stampar 2012-03-01 10:10:19 +00:00
  • 2d3c12d2d0 shorter single line info Miroslav Stampar 2012-03-01 09:10:24 +00:00
  • 37db27b720 turning back on automatic adjusting of delays in time based queries Miroslav Stampar 2012-02-29 15:51:23 +00:00
  • 0205d96d7b minor fix Miroslav Stampar 2012-02-29 15:38:01 +00:00
  • 1bdc07c279 minor update Miroslav Stampar 2012-02-29 15:02:24 +00:00
  • 8b9c5c66cc code refactoring regarding charsetType inside inference/bisection Miroslav Stampar 2012-02-29 14:36:23 +00:00
  • f6f98f1b41 minor improvement Miroslav Stampar 2012-02-29 14:19:59 +00:00
  • 10dd9096f7 one more just in case fix for safeSQLIdentificator naming on MSSQL --tables Miroslav Stampar 2012-02-29 14:05:53 +00:00
  • d06182347f fixing few potential problems Miroslav Stampar 2012-02-29 13:56:40 +00:00
  • c39d85420a removing PGP Key ID from my info too (used only few times in couple of years) Miroslav Stampar 2012-02-29 09:56:41 +00:00
  • f142c0f782 minor update Miroslav Stampar 2012-02-28 14:04:13 +00:00
  • 22b3fa0749 minor update Miroslav Stampar 2012-02-27 15:28:36 +00:00
  • a9bf0297f6 moving injection data to HashDB Miroslav Stampar 2012-02-27 13:44:07 +00:00
  • 68e08d2749 minor fix for not displaying 'None' but None in enumeration when data unavailable Miroslav Stampar 2012-02-27 13:15:10 +00:00
  • a424de3102 minor fix Miroslav Stampar 2012-02-27 12:55:28 +00:00
  • 1e82405bb9 HashDB is now supported in -d too Miroslav Stampar 2012-02-27 12:14:01 +00:00
  • 3909658fc2 few minor just in case updates Miroslav Stampar 2012-02-27 11:15:53 +00:00
  • 85125018a1 minor bug fix Miroslav Stampar 2012-02-25 22:54:32 +00:00
  • 5d307cf886 minor update Miroslav Stampar 2012-02-25 10:54:39 +00:00
  • 06ab3fa134 minor update Miroslav Stampar 2012-02-25 10:53:38 +00:00
  • 74b19a0386 minor update Miroslav Stampar 2012-02-25 10:43:10 +00:00
  • 5b67af3b20 minor update Miroslav Stampar 2012-02-24 15:03:39 +00:00
  • 8a203ef79d making session data strictly dependent on url through HashDB helper functions Miroslav Stampar 2012-02-24 14:58:24 +00:00
  • c36cbbb3ae minor fix Miroslav Stampar 2012-02-24 14:54:10 +00:00
  • 26b33154ab optimal fix related to the last commit Miroslav Stampar 2012-02-24 14:28:41 +00:00
  • 9d6fd2e507 bug fix for --schema --technique=BST Miroslav Stampar 2012-02-24 14:12:19 +00:00
  • f94b91ad87 added helper function for HashDB data storing/retrieval Miroslav Stampar 2012-02-24 13:07:20 +00:00
  • b481c0352f minor update Miroslav Stampar 2012-02-24 11:25:56 +00:00
  • 1f6ce265b9 minor fix Miroslav Stampar 2012-02-24 11:05:04 +00:00
  • 5afbd52b61 more update related to last commits Miroslav Stampar 2012-02-24 10:57:23 +00:00
  • 570d3a19c2 more general fix Miroslav Stampar 2012-02-24 10:53:28 +00:00
  • e8352e504f fixing problems with chars deletition by logging messages in inference mode Miroslav Stampar 2012-02-24 10:48:19 +00:00
  • 71028a81f5 fix for proper retrieval of columns in SQLite Miroslav Stampar 2012-02-24 09:55:13 +00:00
  • f9d2971474 minor just in case fix Miroslav Stampar 2012-02-23 16:37:06 +00:00
  • 7941504c3a minor update Miroslav Stampar 2012-02-23 15:32:36 +00:00
  • 0478e4166a minor justin case fix Miroslav Stampar 2012-02-23 15:19:20 +00:00
  • 086c3a3662 minor fix Miroslav Stampar 2012-02-23 13:31:50 +00:00
  • 82e2f27024 Minor doc update Bernardo Damele 2012-02-23 10:45:52 +00:00
  • da22e82309 minor fix Miroslav Stampar 2012-02-23 10:29:55 +00:00
  • 2866aaf4cf minor fixes Miroslav Stampar 2012-02-23 10:16:58 +00:00